Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12426

Опубликовано: 14 авг. 2017
Источник: debian

Описание

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed9.5.4+dfsg-7package

Примечания

  • https://gitlab.com/gitlab-org/gitlab-ce/issues/35212

  • The fix for git for CVE-2017-1000117 mitgates the issue in gitlab itself.

  • The CVE is for the issue when importing a project via crafted SSH URLs,

  • which becomes ineffective with a fixed git version itself.

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
nvd
почти 8 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
github
около 3 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.