CVE-2024-4835: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.6Fixed in 16.11.3Fixed in 17.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4835?
CVE-2024-4835 has been classified as a high severity vulnerability due to its potential to exfiltrate sensitive user information.
How do I fix CVE-2024-4835?
To address CVE-2024-4835, upgrade GitLab to version 16.10.6 or later, 16.11.3 or later, or 17.0.1 or later.
Which versions of GitLab are affected by CVE-2024-4835?
CVE-2024-4835 affects GitLab versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1.
What type of attack can exploit CVE-2024-4835?
CVE-2024-4835 allows for Cross-Site Scripting (XSS) attacks, enabling attackers to craft malicious pages.
What is the impact of CVE-2024-4835 on users?
The impact of CVE-2024-4835 can lead to the exfiltration of sensitive user information, potentially compromising user accounts.