7.1

CVE-2023-3922

URL Redirection to Untrusted Site ('Open Redirect') in GitLab

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 8.15 < 16.2.8
Gitlab ≫ GitLab SwEdition enterprise Version >= 8.15 < 16.2.8
Gitlab ≫ GitLab SwEdition community Version >= 16.3.0 < 16.3.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.3.0 < 16.3.5
Gitlab ≫ GitLab Version 16.4.0 SwEdition community
Gitlab ≫ GitLab Version 16.4.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.303
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 2.8 3.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
cve@gitlab.com 3 1.3 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:L
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://gitlab.com/gitlab-org/gitlab/-/issues/394770
Vendor Advisory
Issue Tracking
https://hackerone.com/reports/1887323
Permissions Required