CVE-2017-8778

MEDIUM

GitLab < 8.14.9, 8.15.x < 8.15.6, 8.16.x < 8.16.5 - Stored Cross-Site Scripting via SVG Attachment or Avatar

Title source: llm
STIX 2.1

Description

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

References (2)

Core 2
Core References
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://about.gitlab.com/2017/02/15/gitlab-8-dot-16-dot-5-security-release/
Exploit, Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/27471

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 22.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (12)
gitlab/gitlab 8.15.0
gitlab/gitlab 8.15.1
gitlab/gitlab 8.15.2
gitlab/gitlab 8.15.3
gitlab/gitlab 8.15.4
gitlab/gitlab 8.15.5
gitlab/gitlab 8.16.0
gitlab/gitlab 8.16.1
gitlab/gitlab 8.16.2
gitlab/gitlab 8.16.3
... and 2 more
Published May 04, 2017
Tracked Since Feb 18, 2026