CVE-2023-2164: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.2.2 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.1.3 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.0.8
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2164.
What versions of GitLab are affected by CVE-2023-2164?
All versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, and all versions starting from 16.2 before 16.2.2 are affected.
What is the severity of CVE-2023-2164?
The severity of CVE-2023-2164 is medium with a CVSS score of 5.4.
How can an attacker exploit CVE-2023-2164?
An attacker can exploit CVE-2023-2164 by triggering a stored XSS vulnerability via user interaction with a crafted URL.
Are there any references for CVE-2023-2164?
Yes, you can find references for CVE-2023-2164 at the following links: [Reference 1](https://gitlab.com/gitlab-org/gitlab/-/issues/407783), [Reference 2](https://hackerone.com/reports/1940598).