Severity
6.1MEDIUM
EPSS
0.1%
top 76.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 9.1.0 - 10.1.5 Fixed in 10.1.6+2
NVDgitlab/gitlab10.1.010.1.5+2

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-fcwc-pv7g-5mr8: Gitlab Community Edition version 102022-05-13
CVEList
CVE-2017-0917: Gitlab Community Edition version 102018-03-21

📋Vendor Advisories

2
GitLab
CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting2018-03-21
Debian
CVE-2017-0917: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...2017