Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-3092

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.5%
CVSS Severity
CVSS v3 Score 8.7
Products affected by CVE-2024-3092
  • Gitlab » Gitlab » Version: 16.10.0
    cpe:2.3:a:gitlab:gitlab:16.10.0
  • Gitlab » Gitlab » Version: 16.10.1
    cpe:2.3:a:gitlab:gitlab:16.10.1
  • Gitlab » Gitlab » Version: 16.9.0
    cpe:2.3:a:gitlab:gitlab:16.9.0
  • Gitlab » Gitlab » Version: 16.9.1
    cpe:2.3:a:gitlab:gitlab:16.9.1
  • Gitlab » Gitlab » Version: 16.9.2
    cpe:2.3:a:gitlab:gitlab:16.9.2
  • Gitlab » Gitlab » Version: 16.9.3
    cpe:2.3:a:gitlab:gitlab:16.9.3


Contact Us

Shodan ® - All rights reserved