CVE-2024-2279: Stored XSS via autocomplete results

Published Apr 10, 2024
·
Updated

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

Other sources

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature, a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims. This is a high severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N, 8.7). It is now mitigated in the latest release and is assigned CVE-2024-2279.

GitLab

Affected Software

7 affected componentsFixes available
GitLab GitLab>=16.7.0<16.8.6
GitLab GitLab>=16.7.0<16.8.6
GitLab GitLab>=16.9.0<16.9.4
GitLab GitLab>=16.9.0<16.9.4
GitLab GitLab>=16.10.0<16.10.2
GitLab GitLab>=16.10.0<16.10.2
GitLab GitLab>=16.7<16.8.6, >=16.9<16.9.4, >=16.10<16.10.2
16.8.616.9.416.10.2

Remediation

Information

Upgrade to versions 16.8.6, 16.9.4, 16.10.2 or above.

Event History

Apr 12, 2024
CVE Published
via MITRE·12:53 AM
Data Sourced
via MITRE·12:53 AM
RemedyDescriptionSeverityWeakness
Apr 22, 2026
Data Sourced
via GitLab·08:52 AM
DescriptionSeverityAffected Software

Peer vulnerabilities

Found alongside the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of CVE-2024-2279?

CVE-2024-2279 is classified as a moderate severity vulnerability due to its potential for causing stored injection issues in affected versions of GitLab.

2

How do I fix CVE-2024-2279?

To fix CVE-2024-2279, you should upgrade your GitLab instance to version 16.8.7 or later, 16.9.4 or later, or 16.10.2 or later.

3

Which versions of GitLab are affected by CVE-2024-2279?

CVE-2024-2279 affects GitLab versions starting from 16.7 to 16.8.6, 16.9 from 16.9.0 to before 16.9.4, and 16.10 from 16.10.0 to before 16.10.2.

4

What type of attack can CVE-2024-2279 facilitate?

CVE-2024-2279 can potentially enable stored injection attacks through the use of a crafted payload in the autocomplete for issues feature.

5

Is there a workaround for CVE-2024-2279 if I can't update immediately?

Currently, it is recommended to apply updates to address CVE-2024-2279 rather than relying on workarounds, as they may not fully mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203