GitLab is patching a serious vulnerability that could allow unauthorized users to take control of user accounts through cross-site scripting (XSS) attacks

The vulnerability is tracked as CVE-2024-4835 and is an XSS vulnerability in the VS code editor (Web IDE). Attackers can exploit it to steal limited information using specially crafted malicious pages.
Although authentication is not required for a successful attack, user interaction.
See also: UserPro plugin – WordPress: Warning! Critical vulnerability
“Today, we are releasing versions 17.0.1, 16.11.3, and 16.10.6 for GitLab Community Edition (CE) and Enterprise Edition (EE),” GitLab said in a statement regarding the vulnerability fix.
“These releases contain important bug and security , and we strongly recommend that all GitLab installations be upgraded to one of these releases immediately.“.
On Wednesday, the company patched six more vulnerabilities of moderate severity.
GitLab: Vulnerability is actively used in attacks
The GitLab platform is a favorite target, as it hosts important data, including API keys and proprietary code.
See also: Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger
This means that a GitLab account breach can have a significant impact, including attacks , if attackers introduce malicious code into CI/CD environments.
As CISA warned earlier this month, hackers are actively exploiting another account compromise vulnerability that was patched in January. The vulnerability is tracked as CVE-2023-7028 and allows unverified attackers to take control accounts via password reset.

CISA added this GitLab vulnerability to the List of Known Exploitable Vulnerabilities on May 1, ordering US federal agencies to secure their systems by May 22
As technology continues to advance, it is vital for developers and companies to prioritize security and make it a fundamental aspect of their processes. GitLab’s actions to address vulnerabilities demonstrate its dedication to providing a secure platform for collaboration and development.
See also: Veeam warns of critical vulnerability in VBEM
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Beyond applying updates to fix a vulnerability, there are a few additional steps users can take to ensure the security of their GitLab accounts: enabling two-factor authentication, regularly reviewing account activity logs, and regularly updating passwords .As a community-driven platform, GitLab also encourages users to report any vulnerabilities they encounter so they can be addressed promptly.
Source: www.bleepingcomputer.com
