An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
Configurations
History
21 Nov 2024, 07:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/396533 - Exploit, Issue Tracking, Vendor Advisory | |
References | () https://hackerone.com/reports/1889255 - Permissions Required, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
08 Oct 2024, 19:38
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
03 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-201 |
03 Aug 2023, 17:25
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://hackerone.com/reports/1889255 - Permissions Required, Third Party Advisory | |
References | (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/396533 - Exploit, Issue Tracking, Vendor Advisory | |
First Time |
Gitlab
Gitlab gitlab |
|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-668 |
26 Jul 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-26 07:15
Updated : 2024-11-21 07:39
NVD link : CVE-2023-1401
Mitre link : CVE-2023-1401
CVE.ORG link : CVE-2023-1401
JSON object : View
Products Affected
gitlab
- gitlab
CWE