CVE-2023-3500
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.
Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 10.0 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Un XSS reflejado era posible al crear diagramas PlantUML específicos que permitían al atacante realizar acciones arbitrarias en nombre de las víctimas.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-07-04 CVE Reserved
- 2023-08-02 CVE Published
- 2024-09-03 EPSS Updated
- 2024-09-18 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/416902 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 10.0 < 16.0.8 Search vendor "Gitlab" for product "Gitlab" and version " >= 10.0 < 16.0.8" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 10.0 < 16.0.8 Search vendor "Gitlab" for product "Gitlab" and version " >= 10.0 < 16.0.8" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 16.1 < 16.1.3 Search vendor "Gitlab" for product "Gitlab" and version " >= 16.1 < 16.1.3" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 16.1 < 16.1.3 Search vendor "Gitlab" for product "Gitlab" and version " >= 16.1 < 16.1.3" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 16.2 < 16.2.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 16.2 < 16.2.2" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 16.2 < 16.2.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 16.2 < 16.2.2" | enterprise |
Affected
|