Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12426

Опубликовано: 14 авг. 2017
Источник: debian
EPSS Низкий

Описание

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed9.5.4+dfsg-7package

Примечания

  • https://gitlab.com/gitlab-org/gitlab-ce/issues/35212

  • The fix for git for CVE-2017-1000117 mitgates the issue in gitlab itself.

  • The CVE is for the issue when importing a project via crafted SSH URLs,

  • which becomes ineffective with a fixed git version itself.

EPSS

Процентиль: 83%
0.01973
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
nvd
больше 8 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
github
больше 3 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

EPSS

Процентиль: 83%
0.01973
Низкий