MEDIUM

CVE-2024-8179

Gitlab GitLab 2024-12-12 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

Summary dbcve.org

A cross-site scripting (XSS) vulnerability exists in GitLab CE/EE due to improper output encoding of user-supplied data. The vulnerability affects versions 17.3 through 17.6.2 and can be exploited when Content Security Policy (CSP) is not enabled, allowing attackers to inject malicious scripts into web pages viewed by other users.

Mitigation

Upgrade GitLab to version 17.4.6, 17.5.4, or 17.6.2 or later. Alternatively, ensure Content Security Policy (CSP) is enabled as a compensating control until the upgrade can be performed.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.33%
Probability of exploitation in next 30 days
26.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE