Vulnerabilities > Gitlab > Gitlab > 9.2.8
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-03-21 | CVE-2017-0924 | Cross-site Scripting vulnerability in Gitlab Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting. | 4.3 |
2018-03-21 | CVE-2017-0922 | Incorrect Authorization vulnerability in Gitlab Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object. | 5.0 |
2018-03-21 | CVE-2017-0918 | Path Traversal vulnerability in Gitlab Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution. | 6.5 |
2018-03-21 | CVE-2017-0916 | Improper Input Validation vulnerability in Gitlab Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution. | 7.5 |
2018-03-21 | CVE-2017-0915 | Improper Input Validation vulnerability in Gitlab Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution. | 7.5 |
2017-08-14 | CVE-2017-12426 | Improper Input Validation vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import. | 8.8 |