An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.
History

Thu, 13 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 08:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.
Title Improper Neutralization of Input Used for LLM Prompting in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-1427
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-02-13T14:36:00.382Z

Reserved: 2024-04-04T10:30:36.615Z

Link: CVE-2024-3303

cve-icon Vulnrichment

Updated: 2025-02-13T14:35:45.047Z

cve-icon NVD

Status : Received

Published: 2025-02-13T09:15:09.653

Modified: 2025-02-13T09:15:09.653

Link: CVE-2024-3303

cve-icon Redhat

No data.