Severity
6.1MEDIUMNVD
CISA7.8CISA7.5
EPSS
8.1%
top 7.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateAug 18

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages9 packages

NVDgitlab/gitlab15.8.015.10.8+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab> 15.8, <15.10.8, >=15.11, <15.11.7, >=16.0, <16.0.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

3
GHSA
yt-dlp File Downloader cookie leak2023-07-06
GHSA
GHSA-vx2h-m34g-ggpg: An issue has been discovered in GitLab CE/EE affecting all versions starting from 152023-06-07
OSV
CVE-2023-2015: An issue has been discovered in GitLab CE/EE affecting all versions starting from 152023-06-07

💥Exploits & PoCs

4
Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass2025-08-18
Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution2015-11-18
Nuclei
Skype for Business 2019 (SfB) - Blind Server-side Request Forgery
Nuclei
Openfire Administration Console - Authentication Bypass

📋Vendor Advisories

7
Microsoft
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide2024-01-09
Red Hat
cpio: path traversal vulnerability2024-01-04
Microsoft
Skype for Business Remote Code Execution Vulnerability2023-10-10
GitLab
CVE-2023-2015: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.72023-06-07
CISA
Jenkins User Interface (UI) Information Disclosure Vulnerability2023-05-12