CVE-2024-8312
24.10.2024, 10:15
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 15.10.0 ≤ 𝑥 < 17.3.6 |
gitlab | gitlab | 15.10.0 ≤ 𝑥 < 17.3.6 |
gitlab | gitlab | 17.4.0 ≤ 𝑥 < 17.4.3 |
gitlab | gitlab | 17.4.0 ≤ 𝑥 < 17.4.3 |
gitlab | gitlab | 17.5.0 |
gitlab | gitlab | 17.5.0 |
𝑥
= Vulnerable software versions