First published: Wed Apr 05 2023(Updated: )
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=1.0.0<15.8.5 | |
GitLab | >=1.0.0<15.8.5 | |
GitLab | >=15.9.0<15.9.4 | |
GitLab | >=15.9.0<15.9.4 | |
GitLab | =15.10.0 | |
GitLab | =15.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1708 is rated as a high severity vulnerability due to its potential for executing unexpected commands from the victim's clipboard.
To fix CVE-2023-1708, update your GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later.
CVE-2023-1708 affects all GitLab CE/EE versions prior to 15.8.5, 15.9.4, and 15.10.1.
CVE-2023-1708 allows attackers to execute unexpected commands on the victim's machine by leveraging non-printable characters copied from the clipboard.
Currently, the only effective measure against CVE-2023-1708 is to update to a secure version of GitLab as there are no documented workarounds.