MEDIUM

CVE-2024-8648

Gitlab GitLab 2024-11-14 CVSS v3.1
CVSS
6.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

Summary dbcve.org

This is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting versions 16.x through 17.5.x (before patches). Attackers can inject malicious JavaScript code into Analytics Dashboards via a specially crafted URL, potentially allowing session hijacking or actions on behalf of authenticated users.

Mitigation

Upgrade GitLab to version 17.3.7, 17.4.4, 17.5.2 or later. If immediate upgrading is not possible, restrict access to Analytics Dashboards features pending the patch.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.37%
Probability of exploitation in next 30 days
31.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE