MEDIUM

CVE-2017-0917

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
6.1

Description

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

Summary dbcve.org

GitLab Community Edition 10.2.4 contains a persistent cross-site scripting vulnerability in the CI job component due to insufficient input validation. User-supplied data in CI job configurations is not properly sanitized before being stored and rendered, allowing attackers to inject malicious scripts that execute in the browsers of other users viewing CI job output.

Mitigation

Upgrade GitLab to a patched version that addresses input validation in the CI job component, and implement output encoding for CI job data display.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)
CWE-20 Improper Input Validation

EPSS Score

1.25%
Probability of exploitation in next 30 days
68.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE