Medium severity4.8NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-5512
CVE-2023-5512
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.3.0,<16.4.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.3.0,<16.4.4
- Range: from 16.3 before 16.4.4, from 16.5 before 16.5.4, from 16.6 before 16.6.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/427827nvdBroken Link
- hackerone.com/reports/2194607nvdPermissions Required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023