CVE-2023-5612
Missing Authorization in GitLab
- Published
- Jan 26, 2024
- Updated
- Aug 14, 2026
- Assigning CNA
- GitLab
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NLow · next 30 days
- Percentile
- 91.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
Sources
2- CVE-2023-5612Scanner
Nmap NSE to check for CVE-2023-5612
- Review.CVE-2023-5612Exploit
Analysis via script CVE-2023-5612
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.