MEDIUM
CVE-2017-0923
CVSS
6.1
Description
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
Summary dbcve.org
GitLab Community Edition 9.1 contains a persistent cross-site scripting (XSS) vulnerability in the IPython notebooks component due to lack of input validation. Attackers can inject malicious JavaScript through notebook content that executes when other users view the affected notebook.
Mitigation
Upgrade GitLab to a patched version (9.2 or later) and implement proper input validation/sanitization on all notebook content before rendering.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.76%
Probability of exploitation in next 30 days
53.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.