Back

MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

Published Jun 12, 2024

Description

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.10.7, 16.11.4, 17.0.2 or above.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jun 12, 2024
Updated Aug 29, 2024
Reserved Apr 25, 2024
CISA Vulnrichment
Updated Jun 14, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitLab
Published Jun 12, 2024
Updated Aug 29, 2024
Exploited since n/a
EUVD-2024-32755