CVE-2024-6530

HIGH

GitLab <17.2.9/<17.3.5/<17.4.2 - XSS

Title source: llm
STIX 2.1

Description

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

References (2)

Core 2
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/471049
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2567533

Scores

CVSS v3 7.3
EPSS 0.0139
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 17.1.0 - 17.2.9 (2 CPE variants)
Published Oct 10, 2024
Tracked Since Feb 18, 2026