MEDIUM

CVE-2017-0923

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
6.1

Description

Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.

Summary dbcve.org

GitLab Community Edition 9.1 contains a persistent cross-site scripting (XSS) vulnerability in the IPython notebooks component due to lack of input validation. Attackers can inject malicious JavaScript through notebook content that executes when other users view the affected notebook.

Mitigation

Upgrade GitLab to a patched version (9.2 or later) and implement proper input validation/sanitization on all notebook content before rendering.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.76%
Probability of exploitation in next 30 days
53.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE