An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23657 | An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization. |
Fixes
Solution
Upgrade to versions 4.0.5 or above.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-668 | NVD-CWE-Other |
Thu, 03 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Exposure of Sensitive Information to an Unauthorized Actor in GitLab | Insertion of Sensitive Information Into Sent Data in GitLab |
| Weaknesses | CWE-201 |
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-20T04:06:23.275Z
Reserved: 2023-03-14T16:20:00.289Z
Link: CVE-2023-1401
Updated: 2024-08-02T05:49:11.372Z
Status : Analyzed
Published: 2023-07-26T07:15:09.103
Modified: 2025-05-05T14:14:52.670
Link: CVE-2023-1401
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD