CVE-2023-1401
MEDIUMGitLab <4.0.5 - XSS
Title source: llmDescription
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
Scores
CVSS v3
5.0
EPSS
0.0010
EPSS Percentile
26.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Classification
CWE
CWE-201
Status
published
Affected Products (1)
gitlab/gitlab
< 4.0.5
Timeline
Published
Jul 26, 2023
Tracked Since
Feb 18, 2026