PT-2024-5513 · Gitlab · Gitlab Ce/Ee+1

Published

2024-08-07

·

Updated

2024-08-23

·

CVE-2024-6329

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.16 through 17.0.6 GitLab CE/EE versions 17.1 through 17.1.4 GitLab CE/EE versions 17.2 through 17.2.2
Description The issue causes the web interface to fail to render the diff correctly when the path is encoded. This is related to a lack of output encoding or escaping mechanism in the web interface of the GitLab platform, which can allow a remote attacker to impact the integrity of protected information.
Recommendations For versions 8.16 through 17.0.6, update to a version after 17.0.6. For versions 17.1 through 17.1.4, update to a version after 17.1.4. For versions 17.2 through 17.2.2, update to a version after 17.2.2.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2024-06162
BIT-GITLAB-2024-6329
CVE-2024-6329

Affected Products

Gitlab
Gitlab Ce/Ee