GitLab released patched Community Edition and Enterprise Edition versions 17.0.1, 16.11.3, and 16.10.6 to fix multiple security vulnerabilities and bug issues, and urged self-managed customers to upgrade immediately. The most severe issue was a high-severity cross-site scripting flaw in the Web IDE that could enable one-click account takeover, alongside additional medium-severity weaknesses affecting denial of service, CSRF protections, authorization controls, and information disclosure.
The release is associated with several tracked vulnerabilities, including CVE-2024-5258, CVE-2023-7045, CVE-2024-4835, and CVE-2024-2874. GitLab said GitLab.com was already running the patched version when the advisory was published, and the notice also referenced mitigations related to a PDF.js vulnerability and an update for Mattermost as part of the broader security response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
GitLab released Community Edition and Enterprise Edition versions 17.0.1, 16.11.3, and 16.10.6 to address multiple security vulnerabilities and bug fixes, and urged self-managed installations to upgrade immediately. The release fixed a high-severity XSS issue that could enable 1-click account takeover via the Web IDE, along with several medium-severity flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.