Vulnerability Description
A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 16.6.0, < 17.0.5 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/455318Broken Link
- https://gitlab.com/gitlab-org/gitlab/-/issues/455318Broken Link
FAQ
What is CVE-2024-7047?
CVE-2024-7047 is a vulnerability with a CVSS score of 7.7 (HIGH). A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scrip...
How severe is CVE-2024-7047?
CVE-2024-7047 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7047?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.