CVE-2024-8180
MEDIUMGitLab CE/EE <17.3.7-17.5.2 - XSS
Title source: llmDescription
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.
References (3)
Scores
CVSS v3
5.4
EPSS
0.0294
EPSS Percentile
86.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
gitlab/gitlab
< 17.3.7
gitlab/gitlab
< 17.3.7
Timeline
Published
Nov 14, 2024
Tracked Since
Feb 18, 2026