First published: Thu May 04 2017(Updated: )
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <=8.14.9 | |
GitLab | =8.15.0 | |
GitLab | =8.15.1 | |
GitLab | =8.15.2 | |
GitLab | =8.15.3 | |
GitLab | =8.15.4 | |
GitLab | =8.15.5 | |
GitLab | =8.16.0 | |
GitLab | =8.16.1 | |
GitLab | =8.16.2 | |
GitLab | =8.16.3 | |
GitLab | =8.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8778 has been classified as a medium-severity vulnerability due to the potential for XSS attacks.
To mitigate CVE-2017-8778, update GitLab to version 8.14.10, 8.15.6, or 8.16.5 or later.
CVE-2017-8778 affects GitLab versions prior to 8.14.10, 8.15.6, and 8.16.5.
CVE-2017-8778 is an XSS vulnerability that can be exploited through SVG documents in issue attachments or avatars.
You can check your GitLab version against the affected versions listed for CVE-2017-8778 to see if you are vulnerable.