MEDIUM

CVE-2017-0924

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
6.1

Description

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.

Summary dbcve.org

GitLab Community Edition 10.2.4 lacks input validation in the labels component, allowing attackers to inject malicious scripts that gets stored and executed when other users view the labels - a persistent XSS vulnerability.

Mitigation

Implement proper input validation and output encoding on the labels component to sanitize user-supplied content before storage and before rendering.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.76%
Probability of exploitation in next 30 days
53.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE