High severity8.7NVD Advisory· Published Feb 22, 2024· Updated Jun 17, 2026
CVE-2024-1451
CVE-2024-1451
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.9.0
- cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*
- Range: <16.9.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/441457nvdPermissions Required
- hackerone.com/reports/2371126nvdPermissions Required
News mentions
1- GitLab Security Release: 16.9.1, 16.8.3, 16.7.6GitLab Security Releases · Feb 21, 2024