MEDIUM
CVE-2024-4099
CVSS
5.3
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.
Summary dbcve.org
An AI feature in GitLab EE reads unsanitized content, which could allow attackers to hide prompt injection attacks by embedding malicious instructions within unsanitized data processed by the AI feature.
Mitigation
Upgrade GitLab EE to version 17.2.8, 17.3.4, 17.4.1 or later to obtain the security patch that properly sanitizes content processed by AI features.
Weakness (CWE)
CWE-116
EPSS Score
0.3%
Probability of exploitation in next 30 days
22.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.