First published: Wed May 03 2023(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <15.8.5 | |
GitLab | <15.8.5 | |
GitLab | >=15.9<15.9.5 | |
GitLab | >=15.9<15.9.5 | |
GitLab | >=15.10<15.10.1 | |
GitLab | >=15.10<15.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0155 has a medium severity rating due to the potential for open redirects.
To fix CVE-2023-0155, upgrade GitLab to versions 15.8.5, 15.9.4, or 15.10.1 or later.
CVE-2023-0155 affects all versions of GitLab before 15.8.5, 15.9.4, and 15.10.1.
CVE-2023-0155 can lead to open redirects, allowing attackers to potentially mislead users through crafted links.
Users of affected GitLab versions should prioritize upgrading to the latest secure versions to mitigate the risk.