CVE-2023-3922
Description
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.
Summary dbcve.org
GitLab versions 8.15 through 16.2.7, 16.3.0 through 16.3.4, and 16.4.0 contain a vulnerability allowing attackers to hijack certain links and buttons in the GitLab UI, redirecting users to malicious external pages. This is likely an open redirect or UI manipulation flaw in how the application handles link generation and button destinations.
Mitigation
Upgrade GitLab to version 16.2.8, 16.3.5, 16.4.1, or later. For self-hosted deployments, apply the appropriate patch version; for GitLab.com, no action is required as the service is managed by GitLab.