VYPR
Medium severity5.4NVD Advisory· Published Dec 12, 2024· Updated Jun 17, 2026

CVE-2024-8179

CVE-2024-8179

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

Affected products

13

Patches

Vulnerability mechanics

References

2

News mentions

1