High severity8.7NVD Advisory· Published Dec 1, 2023· Updated Jun 17, 2026
CVE-2023-6033
CVE-2023-6033
Description
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
Affected products
6- Range: from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3
from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3+ 3 more
- (no CPE)range: from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.10
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.10,<16.6.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.10,<16.6.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/431201nvdBroken LinkVendor Advisory
- hackerone.com/reports/2236039nvdPermissions RequiredThird Party Advisory
News mentions
1- GitLab Security Release: 16.6.1, 16.5.3, 16.4.3GitLab Security Releases · Nov 30, 2023