An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/396533 | Exploit Issue Tracking Vendor Advisory |
https://hackerone.com/reports/1889255 | Permissions Required Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-26 07:15
Updated : 2024-11-21 07:39
NVD link : CVE-2023-1401
Mitre link : CVE-2023-1401
CVE.ORG link : CVE-2023-1401
JSON object : View
Products Affected
gitlab
- gitlab
CWE