An issue has been discovered in GitLab CE/EE affecting...
Low severity
Unreviewed
Published
Jul 13, 2023
to the GitHub Advisory Database
•
Updated Oct 3, 2024
Description
Published by the National Vulnerability Database
Jul 13, 2023
Published to the GitHub Advisory Database
Jul 13, 2023
Last updated
Oct 3, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.
References