HIGH

CVE-2024-1451

Gitlab GitLab 2024-02-22 CVSS v3.1
CVSS
8.7

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability in GitLab CE/EE versions 16.9 before 16.9.1 allows authenticated users to inject malicious JavaScript via crafted payloads in user profile fields. When other users view the compromised profile, the payload executes in their browsers, enabling session hijacking and arbitrary actions.

Mitigation

Upgrade to GitLab 16.9.1 or later to receive the patch. As an interim measure, restrict or sanitize user profile field inputs until the upgrade can be completed.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

51.47%
Probability of exploitation in next 30 days
98.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE