GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 15.11, < 18.9.7
- >= 18.10, < 18.10.6
- >= 18.11, < 18.11.3
A vulnerability allowing authenticated users to inject HTML and JavaScript into email notifications was identified in GitLab CE/EE. This issue affects all versions from 15.11 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. The vulnerability arose from inadequate input sanitization, which could have led to the execution of malicious scripts in the context of the email recipient.
Exploitation of this vulnerability could result in cross-site scripting (XSS) attacks, where injected scripts are executed in the context of the user's email client.
Users can upgrade to GitLab versions 18.9.7, 18.10.6, or 18.11.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.