CVE-2024-4201: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.11.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances. This is a medium severity issue (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N, 4.4). It is now mitigated in the latest release and is assigned CVE-2024-4201.
Other sources
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.7Fixed in 16.11.4Fixed in 17.0.2 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.10.7 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.11.4 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 17.0.2 - Compensating control
Mitigation is provided by upgrading to GitLab versions 16.10.7, 16.11.4, 17.0.2 or above, which resolves the CVE-2024-4201 cross-site scripting issue.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4201?
CVE-2024-4201 has been classified as a cross-site scripting vulnerability affecting multiple versions of GitLab.
How do I fix CVE-2024-4201?
To fix CVE-2024-4201, you should upgrade to GitLab version 16.10.7 or later, 16.111.4 or later, or 17.0.2.
What versions of GitLab are affected by CVE-2024-4201?
CVE-2024-4201 affects GitLab versions from 5.1 to 16.10.6, from 16.11.0 to 16.111.3, and from 17.0.0 to 17.0.1.
Can CVE-2024-4201 be exploited remotely?
Yes, CVE-2024-4201 can be exploited remotely by crafting malicious XML files that are viewed in raw mode.
What impact does CVE-2024-4201 have on users?
CVE-2024-4201 can lead to cross-site scripting attacks, potentially allowing attackers to execute scripts in the user's browser.