CVE-2023-3500: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-3500?
CVE-2023-3500 is an issue in GitLab CE/EE that affects versions starting from 10.0 before 16.0.8.
What is the severity of CVE-2023-3500?
CVE-2023-3500 has a severity rating of 6.1, which is considered medium.
How can CVE-2023-3500 be exploited?
CVE-2023-3500 can be exploited through a reflected XSS vulnerability when creating specific PlantUML diagrams.
Which versions of GitLab are affected by CVE-2023-3500?
CVE-2023-3500 affects all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, and all versions starting from 16.2 before 16.2.2.
Where can I find more information about CVE-2023-3500?
You can find more information about CVE-2023-3500 on the GitLab issue page (https://gitlab.com/gitlab-org/gitlab/-/issues/416902) and the HackerOne report (https://hackerone.com/reports/2010926).