HIGH

CVE-2023-3922

Gitlab GitLab 2023-09-29 CVSS v3.1
CVSS
7.1

Description

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

Summary dbcve.org

GitLab versions 8.15 through 16.2.7, 16.3.0 through 16.3.4, and 16.4.0 contain a vulnerability allowing attackers to hijack certain links and buttons in the GitLab UI, redirecting users to malicious external pages. This is likely an open redirect or UI manipulation flaw in how the application handles link generation and button destinations.

Mitigation

Upgrade GitLab to version 16.2.8, 16.3.5, 16.4.1, or later. For self-hosted deployments, apply the appropriate patch version; for GitLab.com, no action is required as the service is managed by GitLab.

Weakness (CWE)

CWE-601 Open Redirect

EPSS Score

0.39%
Probability of exploitation in next 30 days
32.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE