Impact
GitLab has an improper neutralization flaw that allows attacker‑controlled content to be rendered in an analytics dashboard table cell. This defect permits injection of JavaScript into rendered pages, enabling behaviors such as session hijacking, credential theft, data exfiltration, or defacement of web pages. The vulnerability is a classic cross‑site scripting flaw (CWE‑79).
Affected Systems
GitLab Community Edition and Enterprise Edition are affected. Versions prior to 19.0.6, prior to 19.1.4 for 19.1, and prior to 19.2.2 for 19.2 are vulnerable. All earlier releases from 18.2 onward are included in that scope.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Potential exploitation would involve accessing the web interface with privileges that allow creation or editing of analytics data, or opening a malicious link that contains crafted input. The web‑based attack vector and lack of additional prerequisites make the flaw likely to be exploitable by authenticated users with access to the dashboard component.
OpenCVE Enrichment