CVE-2018-12605

MEDIUM

GitLab 10.7.x < 10.7.6 - Cross-Site Scripting via url_for Arbitrary Protocol

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/45168

Scores

CVSS v3 5.4
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 10.7.0 - 10.7.6 (2 CPE variants)
Published Aug 03, 2018
Tracked Since Feb 18, 2026