CVE-2017-0917
published 2018-03-21CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.30%
67.1th percentile
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gitlab | < gitlab 10.5.5+dfsg-1 (sid) | gitlab 10.5.5+dfsg-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | 10.1.0 – 10.1.5 | — |
| gitlab | gitlab | 10.2.0 – 10.2.5 | — |
| gitlab | gitlab | 10.3.0 – 10.3.3 | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fcwc-pv7g-5mr8: Gitlab Community Edition version 10
ghsa_unreviewed·2022-05-13
CVE-2017-0917 [MEDIUM] CWE-79 GHSA-fcwc-pv7g-5mr8: Gitlab Community Edition version 10
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
GitLab
CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting
vendor_gitlab·2018-03-21·CVSS 6.1
CVE-2017-0917 [MEDIUM] CWE-79 CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting
CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
Debian
CVE-2017-0917: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...
vendor_debian·2017·CVSS 6.1
CVE-2017-0917 [MEDIUM] CVE-2017-0917: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-21
Published