Loading HuntDB...

GHSA-8w2x-795m-pv4v

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

Related CVEs

Key Information

GHSA ID
GHSA-8w2x-795m-pv4v
Published
April 5, 2023 9:30 PM
Last Modified
April 12, 2023 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.