Loading HuntDB...

GHSA-x2v6-6q9m-6qx9

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

Related CVEs

Key Information

GHSA ID
GHSA-x2v6-6q9m-6qx9
Published
September 29, 2023 9:30 AM
Last Modified
April 4, 2024 7:58 AM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.