Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3362


An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.


Published

2023-07-13T03:15:10.217

Last Modified

2025-03-20T17:00:14.963

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-209
  • Type: Primary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 16.0.6 Yes
Application gitlab gitlab < 16.0.6 Yes
Application gitlab gitlab 16.1.0 Yes
Application gitlab gitlab 16.1.0 Yes

References