Security Advisory

CVE-2023-2181

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-05-12 00:00:00
Last updated 2025-01-24 15:47:03
Assigner GitLab
State PUBLISHED

Description

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.