CVE-2023-2442
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 7, 2023
Updated: Jan 7, 2025
CWE ID 78
Summary
CVE-2023-2442 is a stored XSS vulnerability affecting GitLab CE/EE versions 15.11 before 15.11.7 and 16.0 before 16.0.2. Maliciously crafted merge requests can exploit this issue, allowing attackers to inject malicious code into pages viewed by other users, potentially executing arbitrary actions on their behalf. This vulnerability poses a significant risk to organizations using unpatched versions of GitLab. Users are advised to upgrade to the latest versions as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jenkins Script Security
Affected Vendors
- Jenkins