Impact
GitLab includes an improper neutralization of user-controlled data in pagination controls of an analytics dashboard component, creating a classic cross-site scripting vulnerability (CWE-79). An attacker could inject malicious scripts that execute in the browser context of any user who views the affected dashboard, facilitating theft of credentials, session hijacking, or the execution of arbitrary commands on the client side. The flaw directly jeopardizes confidentiality and integrity of user data and the overall trustworthiness of the GitLab web interface.
Affected Systems
GitLab Community Edition and Enterprise Edition from version 18.2 up to, but not including, 19.0.6, from 19.1 up to, but not including, 19.1.4, and from 19.2 up to, but not including, 19.2.2 are susceptible. All other supported releases are considered secure.
Risk and Exploitability
The CVSS score of 8.7 classifies this as high severity, although the EPSS score is currently unavailable, meaning no published exploitation data exists. It is not listed in the CISA KEV catalog. The likely attack vector is through the web UI where a user engages with the analytics dashboards; an attacker can craft malicious pagination input that will be rendered unsanitized. The absence of an EPSS score does not diminish the potential impact for organizations that have exposed the vulnerable interface.
OpenCVE Enrichment