QID 379183
Date Published: 2024-01-03
QID 379183: GitLab CE/EE Cross-Site Cookies Leakage Vulnerability (CVE-2023-1401)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-1401: In GitLab, DAST scanner leak cross site cookies on redirect during authorization.
Affected Versions:
GitLab CE/EE versions starting from 3.0.29 before 4.0.5
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability causes leakage of cross site cookies on redirect during authorization while DAST scanner.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
Vendor References
- GitLab Security Advisory -
nvd.nist.gov/vuln/detail/CVE-2023-1401
CVEs related to QID 379183
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|