CVE-2024-8648
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.
Summary dbcve.org
This is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting versions 16.x through 17.5.x (before patches). Attackers can inject malicious JavaScript code into Analytics Dashboards via a specially crafted URL, potentially allowing session hijacking or actions on behalf of authenticated users.
Mitigation
Upgrade GitLab to version 17.3.7, 17.4.4, 17.5.2 or later. If immediate upgrading is not possible, restrict access to Analytics Dashboards features pending the patch.