CVE-2018-10379

MEDIUM

GitLab CE/EE <10.5.8-10.7.2 - Persistent XSS

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104491

Scores

CVSS v3 6.1
EPSS 0.0006
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab < 10.5.8 (2 CPE variants)
Published May 31, 2018
Tracked Since Feb 18, 2026