{"id":"CVE-2023-2620","summary":"Insertion of Sensitive Information Into Sent Data in GitLab","details":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.","aliases":["BIT-gitlab-2023-2620"],"modified":"2026-09-11T03:48:14.878597155Z","published":"2023-07-13T02:11:05.008Z","database_specific":{"cna_assigner":"GitLab","cwe_ids":["CWE-201"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2620.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2620.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2620"},{"type":"REPORT","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/410433"},{"type":"PACKAGE","url":"git://git@gitlab.com:gitlab-org/gitlab.git"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/1976206"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"31c24d2d8643ee22211ef544a4538c4420e96dc9"},{"fixed":"6d037533ce72e8b309efcb41b2801a3c8244789d"},{"introduced":"280a09dbca836a6eedf5da1e63953fe8da44bf4c"},{"fixed":"1ca31874e42fbd4b99f6e3c9174a992c053c8e1b"},{"introduced":"4961ad113f3afe23965ac12285eaab31315ab0c6"},{"fixed":"d3582d7719f503ba7e038a1b2e0443a89ddb6429"}],"database_specific":{"extracted_events":[{"introduced":"15.1"},{"fixed":"15.11.10"},{"introduced":"16.0"},{"fixed":"16.0.6"},{"introduced":"16.1"},{"fixed":"16.1.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v16.0.5-ee","v16.1.0-ee","v16.0.4-ee","v16.0.3-ee","v16.0.0-ee"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2620.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"}]}