GitLab has released new patch versions 17.5.1, 17.4.3 , and 17.3.6 for both Community Edition (CE) and Enterprise Edition (EE)to fix an HTML Injection flaw.
See also: New critical GitLab vulnerability allows arbitrary execution of CI/CD pipelines

These updates address a critical HTML Injection vulnerability that could lead to cross-site scripting (XSS) attacks, along with other security and bug fixes.
The main target of this patch is a high-severity HTML Injection flaw found in Global Search . This vulnerability, which affects all versions since 15.10 but does not include recently released patches, allows attackers to inject malicious HTML into the search field in a different view.
This could enable XSS attacks, where malicious scripts are executed in users' browsers, compromising sensitive data and user accounts.
The vulnerability has been assigned as CVE-2024-8312 and has a CVSS score of 8.7, indicating its high impact and ease of exploitation. GitLab has acknowledged the contribution of security researcher joaxcar in identifying this flaw through the HackerOne.
See also: GitLab releases fix for critical SAML bug
GitLab strongly advises all users running builds affected by the HTML injection flaw to upgrade immediately to mitigate potential risks. Patched builds have already been deployed to GitLab.com, ensuring that users of the hosted service are protected.

However, self-managed installations must be manually updated to prevent exploitation. Along with the HTML import patch, the release also addresses a medium severity Denial of Service (DoS) related to XML manifest file imports. This flaw could allow attackers to disrupt services by injecting maliciously crafted XML files.
GitLab's release strategy includes both scheduled bi-monthly updates and ad-hoc patches for critical flaws, reflecting their commitment to maintaining high security standards across all platforms.
Detailed information about each vulnerability will be published to the GitLab issue tracker 30 days after release.
See also: GitLab releases critical security update
An HTML injection flaw, like the one GitLab is addressing with its update, occurs when an attacker can inject malicious HTML code into a web page that is viewed by other users. This vulnerability occurs when web applications fail to properly sanitize user data before displaying it on web pages. As a result, attackers can create inputs that run their own scripts or manipulate the appearance and behavior of the website. The consequences can range from simple defacement to more serious security breaches, such as stealing user credentials or spreading malware.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
