CVE-2023-5612 is a medium-severity vulnerability affecting GitLab versions before 16.6.6, 16.7.4, and 16.8.1, allowing unauthorized disclosure of user email addresses through the tags feed, even when email visibility is disabled. The vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality with no integrity or availability impact, and can be exploited remotely with low complexity. While not actively exploited in the wild (no KEV entry), a Metasploit module exists, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 16.6.6CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.7, < 16.7.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.8, < 16.8.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
< 16.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
< 16.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.