Vulnerability Database

300,830

Total vulnerabilities in the database

CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

  • Published: Jul 13, 2023
  • Updated: Jul 21, 2023
  • CVE: CVE-2023-2620
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.8
  • AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

No CWE or OWASP classifications available.