CVE Vulnerabilities

CVE-2023-3444

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Jul 13, 2023 | Modified: Jul 20, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 15.3.0 (including) 15.11.10 (excluding)
Gitlab Gitlab 16.0.0 (including) 16.0.6 (excluding)
Gitlab Gitlab 16.1.0 (including) 16.1.1 (excluding)

Potential Mitigations

References