CVE-2023-5512

Published Dec 15, 2023

Last updated 6 months ago

Overview

Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.
Source
cve@gitlab.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5.7
Impact score
3.6
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

cve@gitlab.com
CWE-94
nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending

Configurations