CVE Vulnerabilities

CVE-2023-1401

Published: Jul 26, 2023 | Modified: Oct 08, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 3.0.29 (including) 4.0.5 (excluding)

References