Impact
GitLab contains an vulnerability in its Markdown JSON table renderer that fails to properly sanitize user‑controlled data, allowing an authenticated attacker to embed malicious code. When a targeted user views the affected content, the browser executes the code and, without the user’s knowledge on the site.
Affected Systems
All GitLab Community Edition and Enterprise Edition releases from version 15.3 through versions prior to 19.1.8, 19.2.6, and 19.3.2 are affected, regardless of deployment mode or environment.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires an authenticated attacker who can generate malicious Markdown tables that a victim will view; the attack can lead to unauthorized changes to system state.
OpenCVE Enrichment