CRITICAL

CVE-2017-0915

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
9.8

Description

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

Summary dbcve.org

GitLab Community Edition 10.2.4 contains an input validation flaw in the GitlabProjectsImportService that allows remote attackers to inject and execute arbitrary code through the project import functionality.

Mitigation

Upgrade to a patched GitLab version. Until then, restrict or disable the project import feature for untrusted users and monitor for suspicious import activity.

Weakness (CWE)

CWE-77 Command Injection
CWE-20 Improper Input Validation

EPSS Score

5.51%
Probability of exploitation in next 30 days
92.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE