CVE-2024-2279

HIGH

GitLab CE/EE <16.8.6, <16.9.4, <16.10.2 - Stored XSS

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

References (2)

Core 2
Core References
Exploit, Issue Tracking issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/448469
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2404710

Scores

CVSS v3 8.7
EPSS 0.0069
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (4)
GitLab/GitLab 16.10 - 16.10.2
GitLab/GitLab 16.7 - 16.8.6
gitlab/gitlab 16.7.0 - 16.8.6 (2 CPE variants)
GitLab/GitLab 16.9 - 16.9.4
Published Apr 12, 2024
Tracked Since Feb 18, 2026