HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Published Oct 24, 2024
8.7
HIGHCVSS 3.1
EPSS 0.49%
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
Affected products
-
- Version 15.10StatusaffectedConstraints<17.3.6
- Version 17.4StatusaffectedConstraints<17.4.3
- Version 17.5StatusaffectedConstraints<17.5.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 17.3.6, 17.4.3, 17.5.1 or above.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49083 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/481819 issue-trackingpermissions-requiredExploitIssue Tracking
- https://hackerone.com/reports/2659386 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49083 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/481819 | issue-trackingpermissions-requiredExploitIssue Tracking | |
| https://hackerone.com/reports/2659386 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Oct 24, 2024
Updated Oct 24, 2024
Reserved Aug 29, 2024
Link CVE-2024-8312
CISA Vulnrichment
Updated Oct 24, 2024
ENISA EUVD
EUVD-2024-49083 Assigner GitLab
Published Oct 24, 2024
Updated Oct 24, 2024
Exploited since n/a
Link EUVD-2024-49083