An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/389328 | broken link |
https://hackerone.com/reports/1842314 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0508.json | vendor advisory |