CVE-2023-0042

MEDIUM

GitLab CE/EE <15.5.7-15.7.2 - Open Redirect

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 39.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
gitlab/gitlab 11.4.0 - 15.5.7 (2 CPE variants)
Published Jan 12, 2023
Tracked Since Feb 18, 2026