An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Feb 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection. | |
Title | Improper Neutralization of Input Used for LLM Prompting in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-1427 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-02-13T14:36:00.382Z
Reserved: 2024-04-04T10:30:36.615Z
Link: CVE-2024-3303

Updated: 2025-02-13T14:35:45.047Z

Status : Received
Published: 2025-02-13T09:15:09.653
Modified: 2025-02-13T09:15:09.653
Link: CVE-2024-3303

No data.