← Volver al buscador de CVEs

CVE-2026-4332

GitLab

Descripción

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users- browsers due to improper input sanitization.

CVSS 5.4EPSS 0.27899999999999997%Riesgo 0.55
Ver fuente
Publicación
2026-04-08 23:16:59
Versiones afectadas
<18.2,>=18.2,<18.8.9,>=18.9,<18.9.5,>=18.10,<18.10.3
Tipo
Core software
Última modificación
2026-07-24 20:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N