GSSA-2026-05-P6SB4WGITLAB-GSSA-2026-05-P6SB4WMay 7, 20265.1 Medium
Missing browser security response headers
The dashboard shipped without CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, or HSTS, leaving it exposed to clickjacking, MIME-sniffing, and missing the standard defense-in-depth layer against same-origin XSS. Fixed by adding the standard security header set in next.config.ts.
Affected (1)
- gelhaus-solutionscontributer-checker
- ≥ 0.0.0Fixed in 0.0.1
Mitigations
Workarounds
- Have the reverse proxy / CDN inject the missing headers (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, CSP, HSTS) until 0.0.1 is deployed.
- Until headers are in place, instruct admins/reviewers to access the dashboard only from a fresh browser tab (not embedded in third-party pages).
Solutions
- Upgrade to 0.0.1: next.config.ts emits X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, a CSP with frame-ancestors none and an explicit allowlist (including blob: in script-src/worker-src/media-src for Sentry replay), HSTS when behind HTTPS, plus optional Report-To/CSP report-uri pointing at the new SENTRY_CSP_ENDPOINT env var.
Exploits
- Clickjacking: attacker hosts a page with `<iframe src="https://victim/dashboard/projects/<id>/applications/<appId>"></iframe>` positioned under a fake button. A logged-in reviewer clicks the bait button and unknowingly clicks Approve/Deny inside the framed dashboard with their auth cookie attached.
Configurations
- All deployments of 0.0.0 — the missing headers are unconditional.
Overview
No CSP, no X-Frame-Options, no HSTS — clickjacking and MIME-sniffing were possible against the dashboard.
Severity
CVSS v4
5.1 Medium
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- None
- User interaction
- Active
- Confidentiality (vulnerable system)
- None
- Integrity (vulnerable system)
- Low
- Availability (vulnerable system)
- None
- Confidentiality (subsequent system)
- None
- Integrity (subsequent system)
- None
- Availability (subsequent system)
- None
CVSS v3
2.6 Low
2.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- Low
- Availability
- None
Weaknesses (2)
References (5)
- CWE-693: Protection Mechanism Failure (Technical description)
- CWE-1021: Improper Restriction of Rendered UI Layers (Technical description)
- OWASP Secure Headers Project (Technical description)
- MDN — Content Security Policy (Technical description)
- MDN — Strict-Transport-Security (Technical description)
Credits (2)
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausFinder · egelhaus@ennogelhaus.de
Context
Impacts
Clickjacking against approve/deny/role-change actions in the dashboard.
CAPEC-103MIME-sniffing of JSON responses as JS in older browsers.
CAPEC-209Cross-origin Referer leakage of internal IDs (project IDs, application IDs).
Removal of the standard defense-in-depth layer that limits exfiltration channels for any future same-origin XSS.