GitLab CE
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +1 more
- >= 18.1, < 18.1.4
- >= 18.2, < 18.2.2
A vulnerability allowing account takeover has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2. This issue arises from the ability of authenticated users to inject malicious HTML into work item names, potentially leading to exploitation.
Exploitation of this vulnerability could result in unauthorized account takeover.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.