CVE-2023-4522

An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:35

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/406817 - Exploit () https://gitlab.com/gitlab-org/gitlab/-/issues/406817 - Exploit
References () https://hackerone.com/reports/1937213 - Permissions Required () https://hackerone.com/reports/1937213 - Permissions Required
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 4.3

03 Oct 2024, 07:15

Type Values Removed Values Added
CWE CWE-138 CWE-1287

24 Jul 2024, 05:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/', 'source': 'cve@gitlab.com'}

13 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/ -

28 Dec 2023, 14:50

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/406817 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/406817 - Exploit

15 Nov 2023, 12:15

Type Values Removed Values Added
Summary An issue has been discovered in GitLab affecting all versions starting from 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit.

Information

Published : 2023-08-30 08:15

Updated : 2024-11-21 08:35


NVD link : CVE-2023-4522

Mitre link : CVE-2023-4522

CVE.ORG link : CVE-2023-4522


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-1287

Improper Validation of Specified Type of Input

NVD-CWE-noinfo