CVE-2024-1451Cross-site Scripting in Gitlab

Severity
8.7HIGHNVD
EPSS
29.1%
top 3.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateAug 17

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:NExploitability: 2.3 | Impact: 5.8

Affected Packages5 packages

CVEListV5gitlab/gitlab16.9.016.9.1
NVDgitlab/gitlab16.9.0
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-xxcc-244v-rj6x: An issue has been discovered in GitLab CE/EE affecting all versions starting from 162024-02-22
OSV
CVE-2024-1451: An issue has been discovered in GitLab CE/EE affecting all versions starting from 162024-02-22

📋Vendor Advisories

4
Red Hat
kernel: virtio_net: Fix napi_skb_cache_put warning2024-08-17
Red Hat
kernel: HID: core: remove unnecessary WARN_ON() in implement()2024-07-12
GitLab
CVE-2024-1451: An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile pag2024-02-22
Debian
CVE-2024-1451: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro...2024

💬Community

1
Bugzilla
CVE-2024-26658 kernel: bcachefs: grab s_umount only if snapshotting2024-04-02