CVE-2023-6033: XSS and ReDoS in Markdown via Banzai pipeline of Jira
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allowed attacker to execute javascript in victim’s browser.
Other sources
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-6033?
CVE-2023-6033 is a vulnerability in GitLab that allows an attacker to execute JavaScript in a victim's browser through improper neutralization of input in Jira integration configuration.
Which versions of GitLab are affected by CVE-2023-6033?
GitLab versions 15.10 to 16.6.1, 16.5 to 16.5.3, and 16.4 to 16.4.3 are affected by CVE-2023-6033.
What is the severity of CVE-2023-6033?
CVE-2023-6033 has a severity rating of 8.7 (High).
How can I fix CVE-2023-6033?
To fix CVE-2023-6033, it is recommended to update GitLab to version 16.6.1, 16.5.3, or 16.4.3, depending on the affected version.
Where can I find more information about CVE-2023-6033?
More information about CVE-2023-6033 can be found in the GitLab issue #431201 and the associated HackerOne report.