REDHAT-BUG-2428222: High severity GitLab GitLab Community Edition vulnerability
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.5.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.6.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.7.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428222?
The severity of REDHAT-BUG-2428222 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2428222?
To fix REDHAT-BUG-2428222, upgrade to GitLab versions 18.5.5, 18.6.3, or 18.7.1 or later.
What vulnerability does REDHAT-BUG-2428222 address?
REDHAT-BUG-2428222 addresses a stored cross-site scripting vulnerability in GitLab Flavored Markdown.
Which versions of GitLab are affected by REDHAT-BUG-2428222?
GitLab CE/EE versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 are affected.
Who can exploit the vulnerability identified in REDHAT-BUG-2428222?
An authenticated user can exploit the vulnerability identified in REDHAT-BUG-2428222.