CVE-2023-0042Active Exploitation(gitlab / gitlab)

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-02: 1Active Exploitation · 2026-03-02: 1Patch / Workaround · 2026-03-02: 103-02
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • David@davidsheyi
    Active Exploitation

    6/ CVE-2023-0042 highlights vulnerabilities exploited by AI-driven phishing tools. Keep your systems patched to avoid exploitation. #CyberSecurity #AI

    Post summary

    CVE-2023-0042 is being actively exploited by AI-driven phishing tools, and the text urges users to patch systems to mitigate the risk.

    1000063
    557 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more