GitLab contained an information disclosure vulnerability in which a user's email address could be exposed through the tags feed even when the user had disabled email visibility in their profile. The issue affects GitLab Community Edition and Enterprise Edition before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. The flaw results from inconsistent enforcement of profile privacy controls in feed output, allowing sensitive profile data to be retrievable through an alternate application feature.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Proof-of-Concept (PoC) exploit for CVE-2023-5612, a vulnerability in GitLab (versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1) that allows unauthenticated disclosure of user email addresses via the tags RSS feed, even if the user's profile is set to private. The main exploit is implemented as an Nmap NSE script (cve-2023-5612.nse), which automates the process of: 1. Checking if the target is a GitLab instance. 2. Enumerating all available projects via the /api/v4/projects endpoint. 3. For each project, requesting the /-/tags?format=atom endpoint to retrieve the tags RSS feed. 4. Parsing the feed to extract the first occurrence of <name> and <email> tags, which correspond to the project author's username and email address. 5. Outputting the results and saving them to a CSV file. The repository also includes a README.md with detailed vulnerability description, exploitation steps, and usage examples, as well as a docker-compose.yml for setting up a vulnerable GitLab instance for testing. The exploit is network-based, requires no authentication, and targets the HTTP(S) interface of GitLab. No fake or detection-only scripts are present; the provided NSE script is a functional exploit for information disclosure.
This repository provides a proof-of-concept and operational exploit scripts for CVE-2023-5612, a high-severity SSRF vulnerability in GitLab CE/EE webhook handling. The repository contains two main Lua scripts for Nmap's NSE engine: - 'gitlab-ssrf.nse': A script to manually verify SSRF by sending a crafted webhook URL to the GitLab API, targeting an internal address (e.g., 127.0.0.1:8888). It checks the response to confirm if the SSRF is successful. - 'gitlab-ssrf-brute.nse': A brute-force variant that iterates over several common internal addresses to automate the discovery of accessible internal services via SSRF. Both scripts require a valid GitLab Personal Access Token with Maintainer privileges and target the /api/v4/projects/1/hooks endpoint on a vulnerable GitLab instance (typically on port 8080). The README.md provides detailed vulnerability analysis, manual exploitation steps, mitigation advice, and documentation of the scripts' usage. The exploit demonstrates the ability to access internal services from the GitLab server, confirming the SSRF vulnerability. The repository is well-structured, with clear separation between manual and brute-force scripts, and is intended for use in controlled, ethical testing environments.
This repository contains a single Metasploit auxiliary module targeting an information disclosure vulnerability in GitLab (CVE-2023-5612). The module exploits a flaw in the tags RSS/Atom feed, which allows an attacker to enumerate and extract email addresses of users who have authored tags in GitLab projects, even if those users have set their email addresses to private. The module can target a specific project or enumerate all public projects via the GitLab API. It sends HTTP requests to the tags Atom feed endpoint, parses the XML response, and prints out the names and email addresses of tag authors. The code is written in Ruby and is structured as a standard Metasploit auxiliary module, making use of the framework's HTTP client utilities. The main entry point is the 'run' method, which either targets a specific project or enumerates all projects. The exploit is operational and provides actionable intelligence for penetration testers and security researchers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.