PT-2024-29687 · Gitlab · Gitlab

Joaxcaron

·

Published

2024-06-12

·

Updated

2024-07-18

·

CVE-2024-4201

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 5.1 through 16.10.7 GitLab versions 16.11 through 16.11.4 GitLab versions 17.0 through 17.0.2
Description A cross-site scripting issue has been discovered in GitLab. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.
Recommendations For versions 5.1 through 16.10.7, update to version 16.10.7 or later. For versions 16.11 through 16.11.4, update to version 16.11.4 or later. For versions 17.0 through 17.0.2, update to version 17.0.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-4201
CVE-2024-4201

Affected Products

Gitlab