PT-2025-6643 · Gitlab · Gitlab Ce/Ee

Published

2025-02-12

·

Updated

2025-02-17

·

CVE-2024-3303

CVSS v2.0

6.6

Medium

VectorAV:N/AC:H/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 16.0 through 17.6.5 GitLab EE versions 17.7 through 17.7.4 GitLab EE versions 17.8 through 17.8.2
Description An issue was discovered in GitLab EE which allows an attacker to exfiltrate contents of a private issue using prompt injection.
Recommendations For versions 16.0 through 17.6.5, update to version 17.6.5 or later. For versions 17.7 through 17.7.4, update to version 17.7.4 or later. For versions 17.8 through 17.8.2, update to version 17.8.2 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05388
BIT-GITLAB-2024-3303
CVE-2024-3303

Affected Products

Gitlab Ce/Ee