GitLab CE/EE Vulnerability: XSS Through Improper Output Encoding
CVE-2024-8179

Currently unrated

Key Information:

Vendor
GitLab
Vendor
CVE Published:
12 December 2024

Summary

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

References

Timeline

  • Vulnerability published

.