Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.
Related CPE's
a
gitlab
gitlab
6
References
https://hackerone.com/reports/1753423
Permissions RequiredThird Party Advisory
https://hackerone.com/reports/1753423
Permissions RequiredThird Party Advisory
Weaknesses
Primary
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-200
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2023-01-12T03:15:08.957Z
3 years agoLast modified
2025-04-09T12:15:24.870Z
11 months ago