CVE-2023-2015: XSS
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2015?
CVE-2023-2015 is a reflected XSS vulnerability that can allow attackers to manipulate user interactions.
How do I fix CVE-2023-2015?
To fix CVE-2023-2015, upgrade GitLab to versions 15.10.8, 15.11.7, or 16.0.2 or later.
What versions are affected by CVE-2023-2015?
CVE-2023-2015 affects GitLab CE/EE versions from 15.8 to 15.10.8, 15.11 to 15.11.7, and 16.0 to 16.0.2.
What types of GitLab installations are impacted by CVE-2023-2015?
Both GitLab Community Edition and Enterprise Edition installations are impacted by CVE-2023-2015.
Is user data at risk due to CVE-2023-2015?
Yes, user data could be at risk due to the potential for attackers to exploit the reflected XSS vulnerability.