XSS Vulnerability in GitLab Web IDE Component Affects Multiple Versions
CVE-2024-10383
Key Information:
- Vendor
- Gitlab
- Status
- Vendor
- CVE Published:
- 7 February 2025
Badges
Summary
An XSS vulnerability has been identified in the gitlab-web-ide-vscode-fork component that allows an attacker to execute malicious scripts in a user's browser. This issue primarily affects all versions prior to 1.89.1-1.0.0-dev-20241118094343 within the GitLab environment. Specifically, it can occur when loading Jupyter notebook (.ipynb) files in the GitLab web IDE, impacting GitLab CE/EE versions from 15.11 to 17.3 and temporarily affecting subsequent versions (17.4, 17.5, and 17.6). As a result, this flaw exploits the web IDE component, presenting potential security risks for users who handle notebook files.
Affected Version(s)
GitLab VSCode Fork 0 < 1.89.1-1.0.0-dev-20241118094343
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved