Unrated severityNVD Advisory· Published Mar 28, 2024· Updated May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2023-6371
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.
Affected products
3- Range: <16.8.5, >=16.9 <16.9.3, >=16.10 <16.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2257080mitretechnical-descriptionexploit
- gitlab.com/gitlab-org/gitlab/-/issues/433021mitreissue-tracking
News mentions
1- GitLab Security Release: 16.10.1, 16.9.3, 16.8.5GitLab Security Releases · Mar 27, 2024