MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Published Jun 12, 2024
4.4
MEDIUMCVSS 3.1
EPSS 0.48%
Description
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.
Affected products
-
- Version 16.11StatusaffectedConstraints<16.11.4
- Version 17.0StatusaffectedConstraints<17.0.2
- Version 5.1StatusaffectedConstraints<16.10.7
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.10.7, 16.11.4, 17.0.2 or above.
Weaknesses (1)
References (4)
- https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#xss-and-content-injection-when-viewing-raw-xhtml-files-on-ios-devices Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32755 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/458229 issue-trackingpermissions-requiredVendor Advisory
- https://hackerone.com/reports/2473886 technical-descriptionexploitpermissions-requiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#xss-and-content-injection-when-viewing-raw-xhtml-files-on-ios-devices | Release Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32755 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/458229 | issue-trackingpermissions-requiredVendor Advisory | |
| https://hackerone.com/reports/2473886 | technical-descriptionexploitpermissions-requiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jun 12, 2024
Updated Aug 29, 2024
Reserved Apr 25, 2024
Link CVE-2024-4201
CISA Vulnrichment
Updated Jun 14, 2024
ENISA EUVD
EUVD-2024-32755 Assigner GitLab
Published Jun 12, 2024
Updated Aug 29, 2024
Exploited since n/a
Link EUVD-2024-32755