CVE-2023-5512

MEDIUM

GitLab 16.3-16.4.3, 16.5-16.5.3, 16.6-16.6.1 - File Integrity Compromise via HTML-Encoded Filenames

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.

References (2)

Core 2
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/427827
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2194607

Scores

CVSS v3 4.8
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-94
Status published
Products (4)
GitLab/GitLab 16.3 - 16.4.4
gitlab/gitlab 16.3.0 - 16.4.4 (2 CPE variants)
GitLab/GitLab 16.5 - 16.5.4
GitLab/GitLab 16.6 - 16.6.2
Published Dec 15, 2023
Tracked Since Feb 18, 2026