CRITICAL

CVE-2017-0916

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
9.8

Description

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

Summary dbcve.org

GitLab CE 10.3 lacks input validation in the system_hook_push queue when processing web hook data, allowing attackers to inject malicious code through the web hook component that executes on the GitLab server.

Mitigation

Implement strict input validation and sanitization on all web hook data entering the system_hook_push queue; upgrade to a patched GitLab version.

Weakness (CWE)

CWE-77 Command Injection
CWE-20 Improper Input Validation

EPSS Score

5.51%
Probability of exploitation in next 30 days
92.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE