Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
History

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2023-12-01T07:01:38.124Z

Updated: 2024-09-18T04:08:25.191Z

Reserved: 2023-11-08T13:01:15.229Z

Link: CVE-2023-6033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-01T07:15:13.633

Modified: 2023-12-06T18:53:10.447

Link: CVE-2023-6033

cve-icon Redhat

No data.