CVE-2024-8179Cross-site Scripting in Gitlab

Severity
5.4MEDIUMNVD
EPSS
0.5%
top 32.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

CVEListV5gitlab/gitlab17.617.6.2+2
NVDgitlab/gitlab17.3.017.4.6+2
debiandebian/gitlab< gitlab 17.5.5-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-8179: An issue has been discovered in GitLab CE/EE affecting all versions from 172024-12-12
GHSA
GHSA-239w-f2px-h2wv: An issue has been discovered in GitLab CE/EE affecting all versions from 172024-12-12

📋Vendor Advisories

2
GitLab
CVE-2024-8179: An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper outp2024-12-12
Debian
CVE-2024-8179: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 be...2024