MEDIUM

CVE-2024-4099

Gitlab GitLab 2024-09-26 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

Summary dbcve.org

An AI feature in GitLab EE reads unsanitized content, which could allow attackers to hide prompt injection attacks by embedding malicious instructions within unsanitized data processed by the AI feature.

Mitigation

Upgrade GitLab EE to version 17.2.8, 17.3.4, 17.4.1 or later to obtain the security patch that properly sanitizes content processed by AI features.

Weakness (CWE)

CWE-116

EPSS Score

0.3%
Probability of exploitation in next 30 days
22.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE