First published: Thu May 04 2017(Updated: )
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab GitLab | <=8.14.9 | |
GitLab GitLab | =8.15.0 | |
GitLab GitLab | =8.15.1 | |
GitLab GitLab | =8.15.2 | |
GitLab GitLab | =8.15.3 | |
GitLab GitLab | =8.15.4 | |
GitLab GitLab | =8.15.5 | |
GitLab GitLab | =8.16.0 | |
GitLab GitLab | =8.16.1 | |
GitLab GitLab | =8.16.2 | |
GitLab GitLab | =8.16.3 | |
GitLab GitLab | =8.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.