CVE-2023-6033: GitLab
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
Affected products
- GitLab GitLab: from 15.10, before 16.6.1 (fixed in 16.6.1); from 16.4.0, before 16.4.3 (fixed in 16.4.3); from 16.5.0, before 16.5.3 (fixed in 16.5.3)
Published 2023-12-01. Last modified 2026-06-17.