CVE-2024-4099 is a medium-severity vulnerability in GitLab EE versions 16.0 through 17.4.1, where an AI feature could process unsanitized content, enabling prompt injection attacks. This network-exploitable flaw has low attack complexity and could lead to unauthorized information modification, but not confidentiality or availability impacts. While no public exploits or Metasploit modules exist, the vulnerability has garnered some community discussion and media coverage, though it is not currently listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, < 17.2.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.3.0, < 17.3.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
17.4.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:* | ||
>= 16.0, < 17.2.8CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 17.3, < 17.3.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.