Severity
4.3MEDIUMNVD
CISA8.8
EPSS
0.2%
top 55.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 2

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages21 packages

NVDgitlab/gitlab1.2.015.10.8+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=1.2, <15.10.8, >=15.11, <15.11.7, >=16.0, <16.0.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

3
OSV
CVE-2023-2013: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12023-06-07
GHSA
GHSA-r63h-2v62-7gwc: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12023-06-07
GHSA
jplayer Cross Site Scripting vulnerability2022-05-17

📋Vendor Advisories

8
Red Hat
kernel: i40e: Fix kernel crash during reboot when adapter is in recovery mode2025-05-02
GitLab
CVE-2023-2013: An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7,2023-06-07
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability2023-04-11
CISA
Microsoft Internet Explorer Memory Corruption Vulnerability2023-03-30
Microsoft
Microsoft Word Remote Code Execution Vulnerability2023-02-14

💬Community

1
Bugzilla
CVE-2013-1942 CVE-2013-2023 CVE-2013-2022 owncloud: multiple XSS flaws in included Jplayer.as [fedora-all]2013-08-22