CVE-2023-2013
Published: 07 June 2023
Summary
CVE-2023-2013 is a low-severity Improper Restriction of Rendered UI Layers or Frames (CWE-1021) vulnerability in Gitlab Gitlab. Its CVSS base score is 2.6 (Low).
Operationally, ranked at the 45.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-33543
Vulnerability details
An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a…
more
discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.