Опубликовано: 21 мар. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8
Описание
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
esm-apps/xenial | not-affected | code not present |
esm-infra-legacy/trusty | DNE | |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 10.3.4 |
Показывать по
10
EPSS
Процентиль: 79%
0.01291
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
nvd
около 7 лет назад
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
CVSS3: 9.8
debian
около 7 лет назад
Gitlab Community Edition version 10.3 is vulnerable to a lack of input ...
CVSS3: 9.8
github
около 3 лет назад
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
EPSS
Процентиль: 79%
0.01291
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3