MEDIUM
CVE-2023-0523
CVSS
6.1
Description
An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.
Summary dbcve.org
A Cross-Site Scripting (XSS) vulnerability in GitLab allows attackers to inject malicious scripts through a specially crafted email address. This affects GitLab versions 15.6 through 15.10.1 (specifically 15.6 to <15.8.5, 15.9 to <15.9.4, and 15.10 to <15.10.1). The vulnerability has a CVSS score of 6.1 (Medium).
Mitigation
Upgrade GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later to patch this XSS vulnerability.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.64%
Probability of exploitation in next 30 days
49.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.