CRITICAL
CVE-2017-0915
CVSS
9.8
Description
Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.
Summary dbcve.org
GitLab Community Edition 10.2.4 contains an input validation flaw in the GitlabProjectsImportService that allows remote attackers to inject and execute arbitrary code through the project import functionality.
Mitigation
Upgrade to a patched GitLab version. Until then, restrict or disable the project import feature for untrusted users and monitor for suspicious import activity.
Weakness (CWE)
CWE-77
Command Injection
CWE-20
Improper Input Validation
EPSS Score
5.51%
Probability of exploitation in next 30 days
92.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.