MEDIUM
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in GitLab
Published Jun 7, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.76%
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.
Affected products
-
- Version >=12.9, <15.10.8StatusaffectedConstraints-
- Version >=15.11, <15.11.7StatusaffectedConstraints-
- Version >=16.0, <16.0.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0508.json Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/389328 exploitBroken Link
- https://hackerone.com/reports/1842314 Permissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0508.json | Vendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/389328 | exploitBroken Link | |
| https://hackerone.com/reports/1842314 | Permissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jun 7, 2023
Updated Jan 7, 2025
Reserved Jan 25, 2023
Link CVE-2023-0508
CISA Vulnrichment
Updated Jan 7, 2025