CVE-2024-4901
📛 CVE Title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitLab
- CVSS severity
- HIGH
- CVSS score
- 8.7 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N- Effective score
- 8.7 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-79 - Reserved
- 2024-05-15
- Published
- 2024-06-27 01:31 UTC
- Last updated
- 2024-09-17 19:02 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4901.json
- Linked Threat
- CVE-2024-4901 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-44468 - Assigner
- GitLab
- Published
- Jun 26, 2024, 11:31:05 PM
- Updated
- Sep 17, 2024, 5:02:23 PM
- EUVD base score (CVSS 3.1)
-
8.7 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N - EUVD-reported EPSS
- 4.7900
- Vendors
- GitLab
- Products
-
GitLab (16.9 <16.11.5)GitLab (17.1 <17.1.1)GitLab (17.0 <17.0.3)
- Aliases
-
GHSA-7ghr-75pj-w6vc
ENISA description: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | GitLab |
16.9 (affected),
17.0 (affected),
17.1 (affected)
|
— |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
- GitLab Issue #461773 issue-trackingpermissions-required
- HackerOne Bug Bounty Report #2500163 technical-descriptionexploitpermissions-required
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/79.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2024-4901 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44468 rapid7:euvd.enisa.europa.eu
- https://gitlab.com/gitlab-org/gitlab/-/issues/461773 rapid7:gitlab.com
- https://hackerone.com/reports/2500163 rapid7:hackerone.com
- https://www.cve.org/CVERecord?id=CVE-2024-4901 rapid7:www.cve.org
Remediations (17)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days.
2026-08-05 14:57 UTC -
web:cybersecuritynews.com
Microsoft has released its June 2026 Patch Tuesday security updates, addressing a hefty 198 vulnerabilities across its product ecosystem. The June rollout, published on June 9, 2026, stands out not only for its volume but also for the inclusion of three zero-day vulnerabilities that were actively exploited or publicly known before a fix was available. Administrators are urged to prioritize ...
2026-08-05 14:57 UTC -
web:krebsonsecurity.com
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch ...
2026-08-05 14:57 UTC -
web:nvd.nist.gov
Quick Info CVE Dictionary Entry: CVE-2024-4901 NVD Published Date: 06/26/ 2024 NVD Last Modified: 06/17/2026 Source: GitLab Inc.
2026-08-05 14:57 UTC -
web:vulners.com
CVE-2024-4901 affects GitLab CE/EE: a stored XSS vulnerability that could be imported from a project with malicious commit notes. Root cause cited as improper neutralization of input during web page generation. Affected versions: GitLab 16.9-16.11...
2026-08-05 14:57 UTC -
web:www.microsoft.com
Help protect your computing environment by keeping up to date on Microsoft technical security notifications. Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of ...
2026-08-05 14:57 UTC -
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
2026-08-05 14:57 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:39 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 10:39 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 10:39 UTC -
web:www.maketecheasier.com
Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.
2026-05-22 10:39 UTC -
web:www.tomshardware.com
Microsoft released security update KB5034441 on Patch Tuesday to fix a BitLocker encryption bypass vulnerability affecting Windows 10 users. However, some users are experiencing an update failure ...
2026-05-22 10:39 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-22 10:39 UTC -
web:krebsonsecurity.com
But with a threat score of 9.8 out of possible 10 and marked "exploitation more likely," CVE -2025-59287 can be exploited without authentication and is an easy " patch now" candidate.
2026-05-22 10:39 UTC -
web:www.windowslatest.com
Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.
2026-05-22 10:39 UTC -
web:nvd.nist.gov
An official website of the United States government NVD MENU
2026-05-22 10:39 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 10:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-4901.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-4901",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-06-28T03:55:15.710247Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-17T17:02:23.803Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:55:10.235Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "GitLab Issue #461773",
"tags": [
"issue-tracking",
"permissions-required",
"x_transferred"
],
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/461773"
},
{
"name": "HackerOne Bug Bounty Report #2500163",
"tags": [
"technical-description",
"exploit",
"permissions-required",
"x_transferred"
],
"url": "https://hackerone.com/reports/2500163"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "GitLab",
"repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
"vendor": "GitLab",
"versions": [
{
"lessThan": "16.11.5",
"status": "affected",
"version": "16.9",
"versionType": "semver"
},
{
"lessThan": "17.0.3",
"status": "affected",
"version": "17.0",
"versionType": "semver"
},
{
"lessThan": "17.1.1",
"status": "affected",
"version": "17.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program"
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-29T15:04:58.957Z",
"orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"shortName": "GitLab"
},
"references": [
{
"name": "GitLab Issue #461773",
"tags": [
"issue-tracking",
"permissions-required"
],
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/461773"
},
{
"name": "HackerOne Bug Bounty Report #2500163",
"tags": [
"technical-description",
"exploit",
"permissions-required"
],
"url": "https://hackerone.com/reports/2500163"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above."
}
],
"title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab"
}
},
"cveMetadata": {
"assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"assignerShortName": "GitLab",
"cveId": "CVE-2024-4901",
"datePublished": "2024-06-26T23:31:05.422Z",
"dateReserved": "2024-05-15T09:30:34.902Z",
"dateUpdated": "2024-09-17T17:02:23.803Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}