CVE-2023-1708

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
05/04/2023
Last modified:
10/02/2025

Description

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 1.0.0 (including) 15.8.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 1.0.0 (including) 15.8.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 15.9.0 (including) 15.9.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 15.9.0 (including) 15.9.4 (excluding)
cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*