Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 6.8.1  Security Vulnerabilities
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-01-05
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
CVSS Score
8.8
EPSS Score
0.014
Published
2017-08-14
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
CVSS Score
6.1
EPSS Score
0.001
Published
2017-05-04


Contact Us

Shodan ® - All rights reserved