An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
2024-10-24T10:15:03.630
2024-12-13T15:43:23.843
Analyzed
CVSSv3.1: 8.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 17.3.6 | Yes |
Application | gitlab | gitlab | < 17.3.6 | Yes |
Application | gitlab | gitlab | < 17.4.3 | Yes |
Application | gitlab | gitlab | < 17.4.3 | Yes |
Application | gitlab | gitlab | 17.5.0 | Yes |
Application | gitlab | gitlab | 17.5.0 | Yes |