CVE-2023-3906: Improper Validation of Specified Type of Input in GitLab
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.2.8 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.3.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.4.1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3906.
What is the severity of CVE-2023-3906?
The severity of CVE-2023-3906 is low.
Which versions of GitLab EE are affected by CVE-2023-3906?
All versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 are affected by CVE-2023-3906.
What is the impact of CVE-2023-3906?
An authenticated attacker can craft image URLs which bypass the asset proxy.
Are there any known references for CVE-2023-3906?
Yes, you can find more information about CVE-2023-3906 at the following URLs: [reference 1](https://gitlab.com/gitlab-org/gitlab/-/issues/419213), [reference 2](https://hackerone.com/reports/2071411).