CVE-2023-1204: GitLab
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.
Affected products
- GitLab GitLab: from 10.0, before 12.9.8 (fixed in 12.9.8); from 12.10, before 12.10.7 (fixed in 12.10.7); from 13.0, before 13.0.1 (fixed in 13.0.1)
Published 2023-05-03. Last modified 2026-06-17.