« Volver al listado

CVE-2024-10383

Estado: AnalizadaMedia (6.1)—

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-10383",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-10383",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-07T14:35:18.661709Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab-web-ide-vscode-fork:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GitLab",
          "product": "GitLab VSCode Fork",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.89.1-1.0.0-dev-20241118094343",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-02-07T15:15:16.703",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/500785",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://hackerone.com/reports/2765778",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/500785",
      "tags": [
        "Broken Link"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@gitlab.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE"
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en el componente gitlab-web-ide-vscode-fork distribuido a través de CDN que afecta a todas las versiones anteriores a 1.89.1-1.0.0-dev-20241118094343 y utilizado por todas las versiones de GitLab CE/EE a partir de 15.11 antes de 17.3 y que también afectó temporalmente a las versiones 17.4, 17.5 y 17.6, donde era posible un ataque XSS al cargar archivos .ipynb en el IDE web."
    }
  ],
  "lastModified": "2026-06-17T06:55:31.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62E96CBC-9933-4126-BFE1-6FD6D04707CD",
              "versionEndExcluding": "17.3.0",
              "versionStartIncluding": "15.11.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E500AEAA-4822-421F-81D7-9ED5443C4ED8",
              "versionEndExcluding": "17.3.0",
              "versionStartIncluding": "15.11.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FEBC1F7-0AAA-4CA2-B099-3F4218900FB3"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AC3130C-A3AA-403A-85D9-92FD2B8BC091"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97618D0B-B13A-4111-A78E-3BCB4F023382"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "603F1273-E30C-4EBB-AFEA-6713D273C4F3"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A39B04B-D109-467A-82E1-3FE6CBA48FEE"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}