CVE-2023-0508
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jun 7, 2023
Updated: Jan 7, 2025
CWE ID 113
Summary
CVE-2023-0508 is a vulnerability affecting GitLab CE and EE versions, specifically those starting from 15.4 before 15.10.8, 15.11 before 15.11.7, and all versions of 16.0 prior to 16.0.2. This issue enables open redirection through HTTP response splitting in the NPM package API. An attacker could exploit this to redirect users to malicious websites, potentially leading to data theft or unauthorized access. Users are advised to update their GitLab installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.