CVE-2023-2181: GitLab
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.
Affected products
- GitLab GitLab: before 15.9.8 (fixed in 15.9.8); from 15.10.0, before 15.10.7 (fixed in 15.10.7); from 15.11.0, before 15.11.3 (fixed in 15.11.3)
Published 2023-05-12. Last modified 2026-06-17.