Vulnerability record · CVE-2023-6944 · published 4 January 2024
CVE-2023-6944: Redhat red hat developer hub error message information leak vulnerability
Redhat · Red Hat Developer Hub
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
Description
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHBA-2024:5869 | |
| https://access.redhat.com/security/cve/CVE-2023-6944 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2255204 | Issue TrackingVendor Advisory |
| https://access.redhat.com/security/cve/CVE-2023-6944 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2255204 | Issue TrackingVendor Advisory |
Track CVE-2023-6944 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6944), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.