CVE-2024-8312: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8312?
CVE-2024-8312 is considered a moderate severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-8312?
To fix CVE-2024-8312, upgrade to GitLab versions 17.3.6, 17.4.3, or 17.5.1 or later.
What types of attacks can exploit CVE-2024-8312?
CVE-2024-8312 can be exploited to perform XSS attacks through the Global Search field in the GitLab diff view.
Which versions of GitLab are affected by CVE-2024-8312?
CVE-2024-8312 affects GitLab CE/EE versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1.
What should users of GitLab do regarding CVE-2024-8312?
Users of GitLab should immediately upgrade their installations to the patched versions to mitigate the risk posed by CVE-2024-8312.