CVE-2024-7047Cross-site Scripting in Gitlab

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 71.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25
Latest updateAug 27

Description

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

CVEListV5gitlab/gitlab16.617.0.5+2
NVDgitlab/gitlab16.6.017.0.5+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-x8pf-46vx-rg97: A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 162024-07-25

📋Vendor Advisories

3
Red Hat
perl-App-cpanminus: Insecure HTTP in App::cpanminus Allows Code Execution Vulnerability2024-08-27
GitLab
CVE-2024-7047: A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.22024-07-25
Debian
CVE-2024-7047: gitlab - A cross site scripting vulnerability exists in GitLab CE/EE affecting all versio...2024