CVE-2023-1401: GitLab
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
Affected products
- GitLab GitLab: from 3.0.29, before 4.0.5 (fixed in 4.0.5)
Published 2023-07-26. Last modified 2026-06-17.