CVE-2017-8778
MEDIUMGitLab < 8.14.9, 8.15.x < 8.15.6, 8.16.x < 8.16.5 - Stored Cross-Site Scripting via SVG Attachment or Avatar
Title source: llmDescription
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
References (2)
Core 2
Core References
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://about.gitlab.com/2017/02/15/gitlab-8-dot-16-dot-5-security-release/
Exploit, Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/27471
Scores
CVSS v3
6.1
EPSS
0.0007
EPSS Percentile
22.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (12)
gitlab/gitlab
8.15.0
gitlab/gitlab
8.15.1
gitlab/gitlab
8.15.2
gitlab/gitlab
8.15.3
gitlab/gitlab
8.15.4
gitlab/gitlab
8.15.5
gitlab/gitlab
8.16.0
gitlab/gitlab
8.16.1
gitlab/gitlab
8.16.2
gitlab/gitlab
8.16.3
... and 2 more
Published
May 04, 2017
Tracked Since
Feb 18, 2026