Database/Control plane, storage & DevOps
GitLab: stored XSS via pasted HTML in the Content Editor
Impact
Pasted HTML content in the GitLab Content Editor is not sanitized properly, letting an unauthenticated actor plant markup that runs JavaScript in a targeted user's session when that user views the content. Against a self-hosted GitLab that drives cluster CI/CD, the value of the flaw is whatever the victim's session can do - if the victim is a maintainer, that includes pipeline and variable access. Exploitation needs user interaction and the advisory rates attack complexity high, so this is a targeted-phishing-shaped bug rather than mass exploitation. Impact is limited to the browser session; nothing here touches the GitLab host itself.
Who can reach it
Unauthenticated over the network to place the content, but a targeted GitLab user must then view it in their browser. User interaction is required.
What to do
Upgrade self-managed GitLab to 19.1.8, 19.2.6, or 19.3.2 (affected from 19.0). Package upgrade and service restart on the GitLab host - no cluster impact.
References
Related entries
- Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with RittalCVE-2022-40633 · Rittal CMC III cabinet lock / access-card systemMedium
- Keycloak: Redirect scheme filtering bypassed by appending a wildcardCVE-2023-6134 · KeycloakMedium
- Keycloak: Wildcard in the JARM form_post.jwt response modeCVE-2023-6927 · KeycloakMedium
- MinIO (SFTP gateway): The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate asCVE-2025-27414 · MinIO (SFTP gateway)Medium
- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsCVE-2025-4166 · HashiCorp VaultMedium
- Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfsCVE-2021-27363 · Linux iSCSIMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.