QID 379610
QID 379610: Gitlab Multiple Security Vulnerabilities (prior to gitlab- 16.10.2, 16.9.4, 16.8.6)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2024-3092: Stored XSS injected in diff viewer
CVE-2024-2279: Stored XSS via autocomplete results
CVE-2023-6489: Redos on Integrations Chat Messages
CVE-2023-6678: Redos During Parse Junit Test Report
Affected Versions:
GitLab CE/EE: all versions before 16.8.6
GitLab CE/EE: from 16.9 before 16.9.4
GitLab CE/EE: from 16.10 before 16.10.2
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to Stored XSS injected in diff viewer, Stored XSS via autocomplete results, Redos on Integrations Chat Messages, Redos During Parse Junit Test Report
- GitLab Patch Release: 16.10.2, 16.9.4, 16.8.6 -
about.gitlab.com/releases/2024/04/10/patch-release-gitlab-16-10-2-released/
CVEs related to QID 379610
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Patch Release: 16.10.2, 16.9.4, 16.8.6 |
|