An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Oct 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in GitLab | |
Weaknesses | CWE-113 |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2023-06-07T00:00:00
Updated: 2024-10-03T06:23:09.316Z
Reserved: 2023-01-25T00:00:00
Link: CVE-2023-0508
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-07T17:15:09.823
Modified: 2024-11-21T07:37:18.810
Link: CVE-2023-0508
Redhat
No data.