2023-05-12 23:55:26 +02:00
{
"id" : "CVE-2023-2181" ,
"sourceIdentifier" : "cve@gitlab.com" ,
"published" : "2023-05-12T21:15:09.490" ,
2023-05-15 16:00:27 +02:00
"lastModified" : "2023-05-15T12:54:39.287" ,
"vulnStatus" : "Awaiting Analysis" ,
2023-05-12 23:55:26 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 6.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.1 ,
"impactScore" : 4.2
}
]
} ,
"references" : [
{
"url" : "https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2181.json" ,
"source" : "cve@gitlab.com"
} ,
{
"url" : "https://gitlab.com/gitlab-org/gitlab/-/issues/407859" ,
"source" : "cve@gitlab.com"
} ,
{
"url" : "https://hackerone.com/reports/1938185" ,
"source" : "cve@gitlab.com"
}
]
}