Low severity3.1NVD Advisory· Published Dec 1, 2023· Updated Jun 17, 2026
CVE-2023-3443
CVE-2023-3443
Description
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.1.0,<16.4.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.1.0,<16.4.3
- cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*
- (no CPE)range: 12.1 <= versions < 16.4.3, 16.5 <= versions < 16.5.3, 16.6 <= versions < 16.6.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/416497nvdBroken LinkVendor Advisory
- hackerone.com/reports/2036500nvdPermissions RequiredThird Party Advisory
News mentions
1- GitLab Security Release: 16.6.1, 16.5.3, 16.4.3GitLab Security Releases · Nov 30, 2023