vulnerability

FreeBSD: VID-cdb5338d-04ec-11ee-9c88-001b217b3468 (CVE-2023-0921): Gitlab -- Vulnerability

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
Jun 7, 2023
Added
Jun 7, 2023
Modified
Dec 10, 2025

Description

Gitlab reports: Stored-XSS with CSP-bypass in Merge requests ReDoS via FrontMatterFilter in any Markdown fields ReDoS via InlineDiffFilter in any Markdown fields ReDoS via DollarMathPostFilter in Markdown fields DoS via malicious test report artifacts Restricted IP addresses can clone repositories of public projects Reflected XSS in Report Abuse Functionality Privilege escalation from maintainer to owner by importing members from a project Bypassing tags protection in GitLab Denial of Service using multiple labels with arbitrarily large descriptions Ability to use an unverified email for public and commit emails Open Redirection Through HTTP Response Splitting Disclosure of issue notes to an unauthorized user when exporting a project Ambiguous branch name exploitation

Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.