gitlab.com
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1836.json CVE-2023-1836
MEDIUM
Record summary
CVE-2023-1836 has a selected CVSS score of 4.4 (medium).
Description
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLabBrowse GitLab / GitLab | CVE List | >=5.1, <15.9.6 | affected |
| >=15.10, <15.10.5 | affected | ||
| >=15.11, <15.11.1 | affected |
References
4gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/404613 hackerone.com
https://hackerone.com/reports/1923293 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1836