Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 10.3.2  Security Vulnerabilities
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-05-31
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-04-05
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-04-05
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
CVSS Score
9.8
EPSS Score
0.002
Published
2018-03-24
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
CVSS Score
4.3
EPSS Score
0.001
Published
2018-03-22
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
CVSS Score
7.8
EPSS Score
0.052
Published
2018-03-21
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
CVSS Score
7.5
EPSS Score
0.001
Published
2018-03-21
Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.
CVSS Score
9.8
EPSS Score
0.014
Published
2018-03-21
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
CVSS Score
9.8
EPSS Score
0.013
Published
2018-03-21
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-03-21


Contact Us

Shodan ® - All rights reserved