CVE-2023-0523: XSS
An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0523?
CVE-2023-0523 has been classified as a medium severity vulnerability due to its potential for XSS exploitation.
How do I fix CVE-2023-0523?
To fix CVE-2023-0523, update your GitLab installation to version 15.8.5, 15.9.4, or 15.10.1 or later.
What systems are affected by CVE-2023-0523?
CVE-2023-0523 affects all GitLab versions from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1.
What type of vulnerability is CVE-2023-0523?
CVE-2023-0523 is an XSS (Cross-Site Scripting) vulnerability related to handling malicious email addresses.
What could an attacker do with CVE-2023-0523?
An attacker could exploit CVE-2023-0523 to execute arbitrary scripts in the context of a victim's session.