CVE-2023-1204: GitLab

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

Affected products

  • GitLab GitLab: from 10.0, before 12.9.8 (fixed in 12.9.8); from 12.10, before 12.10.7 (fixed in 12.10.7); from 13.0, before 13.0.1 (fixed in 13.0.1)

Published 2023-05-03. Last modified 2026-06-17.