GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
2018-04-05T14:29:00.387
2024-11-21T04:15:12.163
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 10.4.7 | Yes |
Application | gitlab | gitlab | < 10.4.7 | Yes |
Application | gitlab | gitlab | < 10.5.7 | Yes |
Application | gitlab | gitlab | < 10.5.7 | Yes |
Application | gitlab | gitlab | < 10.6.3 | Yes |
Application | gitlab | gitlab | < 10.6.3 | Yes |