← Back to browse · API

CVE-2023-2164

Severity
MEDIUM
CVSS
5.4
EPSS
0.64975
Risk score
44.34
CISA KEV
No
PoC
No
Published
2023-08-01
Modified
2025-11-20
First seen
2026-08-07
Aliases
EUVD-2023-33681, GHSA-4VC2-WM37-4628
Products
GitLab:GitLab 15.9 <16.0.8, GitLab:GitLab 16.1.0 <16.1.3, GitLab:GitLab 16.2.0 <16.2.2
Sources
euvd EUVD-2023-33681

Description

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

References