CVE-2024-10383: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab VSCode Fork
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10383?
CVE-2024-10383 is classified as a high severity vulnerability due to its potential impact on affected versions of GitLab and the gitlab-web-ide-vscode-fork component.
How do I fix CVE-2024-10383?
To fix CVE-2024-10383, upgrade the gitlab-web-ide-vscode-fork component to version 1.89.1 or later, and ensure that GitLab CE/EE is updated to a version greater than 17.3.
Which versions are affected by CVE-2024-10383?
CVE-2024-10383 affects all versions of gitlab-web-ide-vscode-fork prior to 1.89.1-1.0.0-dev-20241118094343 and all GitLab CE/EE versions from 15.11 up to, but not including, 17.3.
How does CVE-2024-10383 impact GitLab users?
CVE-2024-10383 may expose sensitive user data and compromise the security posture of GitLab users utilizing the affected components.
What components are affected by CVE-2024-10383?
The components affected by CVE-2024-10383 include gitlab-web-ide-vscode-fork and the broader GitLab CE/EE application.