CVE-2023-1708: Command Injection
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1708?
CVE-2023-1708 is rated as a high severity vulnerability due to its potential for executing unexpected commands from the victim's clipboard.
How do I fix CVE-2023-1708?
To fix CVE-2023-1708, update your GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later.
Which versions of GitLab are affected by CVE-2023-1708?
CVE-2023-1708 affects all GitLab CE/EE versions prior to 15.8.5, 15.9.4, and 15.10.1.
What impact does CVE-2023-1708 have on users?
CVE-2023-1708 allows attackers to execute unexpected commands on the victim's machine by leveraging non-printable characters copied from the clipboard.
Is there a workaround for CVE-2023-1708 until I can update?
Currently, the only effective measure against CVE-2023-1708 is to update to a secure version of GitLab as there are no documented workarounds.