An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-26T23:31:05.422Z

Updated: 2024-06-28T13:08:59.344Z

Reserved: 2024-05-15T09:30:34.902Z


Link: CVE-2024-4901

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T00:15:12.263

Modified: 2024-06-27T12:47:19.847


Link: CVE-2024-4901

JSON object: View

cve-icon Redhat Information

No data.

CWE