MEDIUM
CVE-2024-6530
CVSS
5.4
Description
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.
Summary dbcve.org
Cross-site scripting (XSS) vulnerability in GitLab's OAuth application authorization flow. An attacker can inject malicious HTML/JavaScript through the application authorization page, which renders under specific circumstances allowing session hijacking or credential theft.
Mitigation
Upgrade GitLab to version 17.2.9, 17.3.5, or 17.4.2 (or later) to patch the XSS vulnerability in the OAuth application authorization component.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
2.17%
Probability of exploitation in next 30 days
81.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.