CVE-2024-8312
CVE-2024-8312
8.7
HighPublished:
Last updated:
Source:cve@gitlab.com
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- None
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
References
cve@gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/481819cve@gitlab.com
https://hackerone.com/reports/2659386