PT-2023-26838 · Gitlab · Gitlab

Ammar2

·

Publicado

2023-09-29

·

Atualizado

2025-03-20

·

CVE-2023-3922

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GitLab versions 8.15 through 16.2.7 GitLab versions 16.3 through 16.3.4 GitLab versions 16.4 through 16.4.0
Description An issue has been discovered in GitLab, allowing some links and buttons on the GitLab UI to be hijacked to a malicious page.
Recommendations For versions 8.15 through 16.2.7, update to version 16.2.8 or later. For versions 16.3 through 16.3.4, update to version 16.3.5 or later. For versions 16.4 through 16.4.0, update to version 16.4.1 or later.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-GITLAB-2023-3922
CVE-2023-3922

Produtos afetados

Gitlab