Impact
GitLab contains an XSS flaw that can be triggered by an authenticated developer when the CI job modal renders untrusted HTML. By injecting malicious code into this modal, an attacker could execute actions in the context of the developer’s session, potentially accessing sensitive data or further escalating privileges. The vulnerability stems from improper sanitization of HTML content, which is a classic cross‑site scripting weakness.
Affected Systems
The flaw affects GitLab Community Edition and Enterprise Edition, specifically all releases from 19.2 up to but not including 19.2.2. Users running any 19.2.x version before the 19.2.2 update are impacted.
Risk and Exploitability
The CVSS score of 7.7 classifies it as high severity. With no EPSS score available, the likelihood of exploitation cannot be precisely measured, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The attack vector is likely restricted to authenticated developers who have permission to view or edit CI job modals, so exposure is limited to organizations with a large self‑managed developer workforce. The risk is therefore significant for environments where developers retain elevated privileges, but it does not represent an uncontrolled remote exploitation vector for unauthenticated users.
OpenCVE Enrichment