Arbitrary API PUT Requests via User Name Input Sanitization Vulnerability in GitLab CE/EE

Arbitrary API PUT Requests via User Name Input Sanitization Vulnerability in GitLab CE/EE

CVE-2023-5933 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

Learn more about our Api Penetration Testing.