← Back to browse · API

CVE-2023-2442

Severity
HIGH
CVSS
8.7
EPSS
0.96058
Risk score
68.42
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2025-01-07
First seen
2026-08-07
Aliases
EUVD-2023-33927, GHSA-8F3H-5JCR-R8CM
Products
GitLab:GitLab 15.11, <15.11.7, GitLab:GitLab 16.0, <16.0.2
Sources
euvd EUVD-2023-33927

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

References