CVE-2024-8180Cross-site Scripting in Gitlab

Severity
5.4MEDIUMNVD
EPSS
3.1%
top 13.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

CVEListV5gitlab/gitlab17.317.3.7+2
NVDgitlab/gitlab17.3.017.3.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-p932-x66g-q6cc: An issue has been discovered in GitLab CE/EE affecting all versions from 172024-11-14

📋Vendor Advisories

2
GitLab
CVE-2024-8180: An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper outp2024-11-14
Debian
CVE-2024-8180: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 be...2024