GitLab XSS Vulnerability Affects Sensitive User Information
CVE-2024-4835
8HIGH
Summary
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.
Affected Version(s)
GitLab < 16.10.6
GitLab < 16.11.3
GitLab < 17.0.1
News Articles
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
First article discovered by Security-Insider
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database1 News Article(s)
Credit
Thanks [matanber](https://hackerone.com/matanber) for reporting this vulnerability through our HackerOne bug bounty program