GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- < 18.1.5
- >= 18.2, < 18.2.5
- >= 18.3, < 18.3.1
A vulnerability exists in GitLab CE/EE in all versions prior to 18.1.5, 18.2 prior to 18.2.5, and 18.3 prior to 18.3.1. Under certain conditions, this vulnerability could have allowed an authenticated attacker to inject malicious code that appears benign in the web interface. This was possible by exploiting the confusion between branches and tags during repository imports.
Exploitation of this vulnerability could lead to the unauthorized distribution of malicious code within the web interface, creating a risk of code execution or other harmful effects, depending on the nature of the injected code.
Users are advised to upgrade to GitLab CE/EE versions 18.1.5, 18.2.5, or 18.3.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.