CVE-2023-2164 is a stored Cross-Site Scripting (XSS) vulnerability affecting GitLab versions 15.9 through 16.0.7, 16.1 through 16.1.2, and 16.2 through 16.2.1, specifically within the WebIDE beta. An attacker could trigger this vulnerability through user interaction with a specially crafted URL. With a CVSS score of 5.4 (Medium), it requires low privileges and user interaction, leading to potential low impact on confidentiality and integrity. While not listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 96/100 indicate a significant likelihood of exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), but it has garnered community discussion and media coverage, suggesting active awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.9, < 16.0.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.9, < 16.0.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.1, < 16.1.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.1, < 16.1.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.2, < 16.2.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.