PT-2024-9136 · Gitlab · Gitlab Ce/Ee+1

Joaxcaron

·

Published

2024-10-23

·

Updated

2024-12-13

·

CVE-2024-8312

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 15.10 through 17.3.5 GitLab CE/EE versions 17.4 through 17.4.2 GitLab CE/EE versions 17.5 through 17.5.0
Description: An issue has been discovered in GitLab CE/EE that could allow an attacker to inject HTML into the Global Search field on a diff view, leading to cross-site scripting (XSS) attacks. This is related to the lack of protection measures for the web page structure, which could enable a remote attacker to conduct inter-site script attacks.
Recommendations: For GitLab CE/EE versions 15.10 through 17.3.5, update to version 17.3.6 or later. For GitLab CE/EE versions 17.4 through 17.4.2, update to version 17.4.3 or later. For GitLab CE/EE versions 17.5 through 17.5.0, update to version 17.5.1 or later. As a temporary workaround, consider restricting access to the Global Search field on diff views until a patch is available.

Exploit

Fix

XSS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-10822
BDU:2024-10823
BIT-GITLAB-2024-8312
CVE-2024-8312

Affected Products

Gitlab
Gitlab Ce/Ee