Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9243

Опубликовано: 05 апр. 2018
Источник: debian
EPSS Низкий

Описание

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed10.6.3+dfsg-1package

Примечания

  • https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/

EPSS

Процентиль: 24%
0.0008
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
nvd
больше 7 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
github
больше 3 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

EPSS

Процентиль: 24%
0.0008
Низкий