MEDIUM

CVE-2024-6530

Gitlab GitLab 2024-10-10 CVSS v3.1
CVSS
5.4

Description

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

Summary dbcve.org

Cross-site scripting (XSS) vulnerability in GitLab's OAuth application authorization flow. An attacker can inject malicious HTML/JavaScript through the application authorization page, which renders under specific circumstances allowing session hijacking or credential theft.

Mitigation

Upgrade GitLab to version 17.2.9, 17.3.5, or 17.4.2 (or later) to patch the XSS vulnerability in the OAuth application authorization component.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

2.17%
Probability of exploitation in next 30 days
81.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE