MEDIUM

CVE-2023-0523

Gitlab GitLab 2023-04-05 CVSS v3.1
CVSS
6.1

Description

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

Summary dbcve.org

A Cross-Site Scripting (XSS) vulnerability in GitLab allows attackers to inject malicious scripts through a specially crafted email address. This affects GitLab versions 15.6 through 15.10.1 (specifically 15.6 to <15.8.5, 15.9 to <15.9.4, and 15.10 to <15.10.1). The vulnerability has a CVSS score of 6.1 (Medium).

Mitigation

Upgrade GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later to patch this XSS vulnerability.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.64%
Probability of exploitation in next 30 days
49.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE