MEDIUM
CVE-2024-4901
CVSS
5.4
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
Summary dbcve.org
A stored XSS vulnerability exists in GitLab CE/EE where malicious commit notes containing XSS payloads can be imported from one project into another. When users view the imported commit notes, the embedded JavaScript executes in their browser context.
Mitigation
Upgrade GitLab to version 16.11.5, 17.0.3, or 17.1.1 or later. Audit projects for any imported commit notes from untrusted sources prior to patching.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
33.02%
Probability of exploitation in next 30 days
98.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.