An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Oct 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:* |
Fri, 27 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 26 Sep 2024 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection. | |
Title | Improper Encoding or Escaping of Output in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-116 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-09-26T23:02:15.810Z
Updated: 2024-09-27T15:48:49.456Z
Reserved: 2024-04-23T20:30:35.566Z
Link: CVE-2024-4099
Vulnrichment
Updated: 2024-09-27T15:48:45.664Z
NVD
Status : Analyzed
Published: 2024-09-26T23:15:02.873
Modified: 2024-10-04T17:33:45.613
Link: CVE-2024-4099
Redhat
No data.