CVE-2018-9244Cross-site Scripting in Gitlab

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 77.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5
Latest updateMay 14

Description

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDgitlab/gitlab9.210.4.7+2
debiandebian/gitlab< gitlab 10.6.3+dfsg-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-wmqm-jhj6-rhr7: GitLab Community and Enterprise Editions version 92022-05-14

📋Vendor Advisories

2
GitLab
CVE-2018-9244: GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component l2018-04-05
Debian
CVE-2018-9244: gitlab - GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable t...2018