Vulnerability CVE-2023-1204


Published: 2023-05-03

Description:
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

 References:
https://gitlab.com/gitlab-org/gitlab/-/issues/394745
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1204.json
https://hackerone.com/reports/1881598

Copyright 2026, cxsecurity.com

 

Back to Top