CVE-2024-4835Cross-site Scripting in Gitlab

Severity
8.2HIGHNVD
EPSS
7.5%
top 8.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 23

Description

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.7

Affected Packages4 packages

CVEListV5gitlab/gitlab15.1116.10.6+2
NVDgitlab/gitlab15.11.016.10.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-4835: A XSS condition exists within GitLab in versions 152024-05-23
GHSA
GHSA-9r4p-g7c7-2c4r: A XSS condition exists within GitLab in versions 152024-05-23

📋Vendor Advisories

2
GitLab
CVE-2024-4835: A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an2024-05-23
Debian
CVE-2024-4835: gitlab - A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 bef...2024

🕵️Threat Intelligence

1
Bleepingcomputer
High-severity GitLab flaw lets attackers take over accounts2024-05-23