CVE-2023-2620: GitLab
Low severity, CVSS 3.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.
Affected products
- GitLab GitLab: from 15.1.0, before 15.11.10 (fixed in 15.11.10); from 16.0.0, before 16.0.6 (fixed in 16.0.6); from 16.1.0, before 16.1.1 (fixed in 16.1.1)
Published 2023-07-13. Last modified 2026-06-17.