Security Advisory
CVE-2023-3500
4.8
MEDIUM
Vulnerability Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.
Published Date
August 2, 2023
Official Source
NIST NVD Advisory