GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 17.9, < 18.3.6
- >= 18.4, < 18.4.4
- >= 18.5, < 18.5.2
A prompt injection vulnerability has been identified in GitLab Enterprise Edition (EE) versions 17.9 prior to 18.3.6, 18.4 prior to 18.4.4, and 18.5 prior to 18.5.2. This vulnerability could have allowed an authenticated user to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.
Exploitation of this vulnerability could lead to unauthorized information disclosure from confidential issues.
Users are advised to upgrade to GitLab EE versions 18.5.2, 18.4.4, or 18.3.6.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.