Low severity3.5NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026
CVE-2023-3906
CVE-2023-3906
Description
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.3,<16.2.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.3,<16.2.8
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
- Range: from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/419213nvdIssue TrackingVendor Advisory
- hackerone.com/reports/2071411nvdPermissions Required
News mentions
1- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023