CVE-2017-0917
Severity
6.1MEDIUM
EPSS
0.1%
top 76.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13
Description
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
▶CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 9.1.0 - 10.1.5 Fixed in 10.1.6+2
Also affects: Debian Linux 9.0
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting↗2018-03-21
Debian▶
CVE-2017-0917: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...↗2017