Description
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 16.10.6, 16.11.3, 17.0.1 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44417 | A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information. |
References
History
Mon, 16 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:* |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T15:33:50.607Z
Reserved: 2024-05-13T10:02:17.492Z
Link: CVE-2024-4835
Updated: 2024-08-01T20:55:10.129Z
Status : Analyzed
Published: 2024-05-23T07:15:09.683
Modified: 2024-12-16T15:10:13.577
Link: CVE-2024-4835
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD