CVE-2023-2015
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-2015 is a reflective Cross-Site Scripting (XSS) vulnerability affecting multiple versions of GitLab CE/EE. Specifically, the flaw was found in the abuse reports feature, impacting all versions of GitLab starting from 15.8 before 15.10.8, all versions of 15.11 before 15.11.7, and all versions of 16.0 before 16.0.2. This issue allows attackers to inject malicious scripts into a webpage, potentially enabling them to steal data or perform unauthorized actions on behalf of the victims. Users are urged to update their GitLab installations as soon as possible to address this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.