CVE-2018-9243
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests).
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gitlab/gitlab
- Source
- cve@mitre.org
References
- https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/42028Exploit, Vendor Advisory
- https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/42028Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.