CVE-2018-9244

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/04/2018
Last modified:
27/02/2019

Description

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 9.2 (including) 10.4.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 9.2 (including) 10.4.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 10.5.0 (including) 10.5.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.5.0 (including) 10.5.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 10.6.0 (including) 10.6.3 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.6.0 (including) 10.6.3 (excluding)