Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8186


An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.


Published

2025-03-03T10:15:09.937

Last Modified

2025-03-06T14:58:21.443

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.7.6 Yes
Application gitlab gitlab < 17.7.6 Yes
Application gitlab gitlab < 17.8.4 Yes
Application gitlab gitlab < 17.8.4 Yes
Application gitlab gitlab 17.9.0 Yes
Application gitlab gitlab 17.9.0 Yes

References