CVE-2017-0923
published 2018-03-21CVE-2017-0923: Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.77%
51.5th percentile
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 10.5.5+dfsg-1 (sid) | gitlab 10.5.5+dfsg-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qc4-p4r5-q24g: Gitlab Community Edition version 9
ghsa_unreviewed·2022-05-13
CVE-2017-0923 [MEDIUM] CWE-79 GHSA-4qc4-p4r5-q24g: Gitlab Community Edition version 9
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
GitLab
CVE-2017-0923: Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site s
vendor_gitlab·2018-03-21·CVSS 6.1
CVE-2017-0923 [MEDIUM] CWE-79 CVE-2017-0923: Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site s
CVE-2017-0923: Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
Debian
CVE-2017-0923: gitlab - Gitlab Community Edition version 9.1 is vulnerable to lack of input validation i...
vendor_debian·2017·CVSS 6.1
CVE-2017-0923 [MEDIUM] CVE-2017-0923: gitlab - Gitlab Community Edition version 9.1 is vulnerable to lack of input validation i...
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-21
Published