Skip to content

Commit 05a7698

Browse files
committed
automatic module_metadata_base.json update
1 parent e20558e commit 05a7698

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

db/modules_metadata_base.json

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21677,6 +21677,68 @@
2167721677

2167821678
]
2167921679
},
21680+
"auxiliary_gather/gitlab_tags_rss_feed_email_disclosure": {
21681+
"name": "GitLab Tags RSS feed email disclosure",
21682+
"fullname": "auxiliary/gather/gitlab_tags_rss_feed_email_disclosure",
21683+
"aliases": [
21684+
21685+
],
21686+
"rank": 300,
21687+
"disclosure_date": "2024-01-25",
21688+
"type": "auxiliary",
21689+
"author": [
21690+
"n00bhaxor",
21691+
"erruquill"
21692+
],
21693+
"description": "An issue has been discovered in GitLab affecting all versions\n before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.\n It is possible to read the user email address via tags feed\n although the visibility in the user profile has been disabled.",
21694+
"references": [
21695+
"URL-https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/",
21696+
"URL-https://hackerone.com/reports/2208790",
21697+
"CVE-2023-5612"
21698+
],
21699+
"platform": "",
21700+
"arch": "",
21701+
"rport": 80,
21702+
"autofilter_ports": [
21703+
80,
21704+
8080,
21705+
443,
21706+
8000,
21707+
8888,
21708+
8880,
21709+
8008,
21710+
3000,
21711+
8443
21712+
],
21713+
"autofilter_services": [
21714+
"http",
21715+
"https"
21716+
],
21717+
"targets": null,
21718+
"mod_time": "2024-03-06 17:37:33 +0000",
21719+
"path": "/modules/auxiliary/gather/gitlab_tags_rss_feed_email_disclosure.rb",
21720+
"is_install_path": true,
21721+
"ref_name": "gather/gitlab_tags_rss_feed_email_disclosure",
21722+
"check": false,
21723+
"post_auth": false,
21724+
"default_credential": false,
21725+
"notes": {
21726+
"Stability": [
21727+
"crash-safe"
21728+
],
21729+
"Reliability": [
21730+
21731+
],
21732+
"SideEffects": [
21733+
21734+
]
21735+
},
21736+
"session_types": false,
21737+
"needs_cleanup": false,
21738+
"actions": [
21739+
21740+
]
21741+
},
2168021742
"auxiliary_gather/grandstream_ucm62xx_sql_account_guess": {
2168121743
"name": "Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump",
2168221744
"fullname": "auxiliary/gather/grandstream_ucm62xx_sql_account_guess",

0 commit comments

Comments
 (0)