An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
Configurations
History
21 Nov 2024, 07:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/396533 - Exploit, Issue Tracking, Vendor Advisory | |
References | () https://hackerone.com/reports/1889255 - Permissions Required, Third Party Advisory |
08 Oct 2024, 19:38
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
03 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-201 |
26 Jul 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-26 07:15
Updated : 2024-11-21 07:39
NVD link : CVE-2023-1401
Mitre link : CVE-2023-1401
CVE.ORG link : CVE-2023-1401
JSON object : View
Products Affected
gitlab
- gitlab
CWE