CVE-2023-5933: Arbitrary API PUT requests via HTML injection in user’s name
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5933?
The severity of CVE-2023-5933 is classified as critical due to improper input sanitization that allows arbitrary API PUT requests.
How do I fix CVE-2023-5933?
To fix CVE-2023-5933, update GitLab to versions 16.6.6, 16.7.4, or 16.8.1 or later.
Which versions of GitLab are affected by CVE-2023-5933?
CVE-2023-5933 affects GitLab CE/EE versions 13.7 to 16.6.6, 16.7 to 16.7.4, and 16.8 to 16.8.0.
What type of vulnerability is CVE-2023-5933?
CVE-2023-5933 is an input validation vulnerability that can lead to improper handling of API requests.
Is there a workaround for CVE-2023-5933?
Currently, the recommended solution for CVE-2023-5933 is to apply the latest updates to GitLab, as there are no specific workaround techniques.