CVE-2023-2442
07.06.2023, 16:15
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 15.11.0 ≤ 𝑥 < 15.11.7 |
gitlab | gitlab | 15.11.0 ≤ 𝑥 < 15.11.7 |
gitlab | gitlab | 16.0.0 ≤ 𝑥 < 16.0.2 |
gitlab | gitlab | 16.0.0 ≤ 𝑥 < 16.0.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References