MEDIUM

CVE-2024-4901

Gitlab GitLab 2024-06-27 CVSS v3.1
CVSS
5.4

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

Summary dbcve.org

A stored XSS vulnerability exists in GitLab CE/EE where malicious commit notes containing XSS payloads can be imported from one project into another. When users view the imported commit notes, the embedded JavaScript executes in their browser context.

Mitigation

Upgrade GitLab to version 16.11.5, 17.0.3, or 17.1.1 or later. Audit projects for any imported commit notes from untrusted sources prior to patching.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

33.02%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE