Back to search

CVE-2017-8778

MEDIUM
6.1NVD

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

CVSS v3.0 Score

6.1
/ 10.0
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Information

Published
4 mai 2017
Updated
20 avr. 2025
Status
Deferred
Source
cve@mitre.org

Affected products

gitlab gitlab
Versions : 8.14.9, 8.15.0, 8.15.1, 8.15.2, 8.15.3

Weaknesses (CWE)

CWE-79

Similar CVEs

Other vulnerabilities of type CWE-79

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring