PT-2018-5143 · Gitlab · Gitlab Ce/Ee+1

Publicado

2018-03-18

·

Atualizado

2019-10-09

·

CVE-2017-0916

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitlab Community Edition version 10.3
Description The issue is related to a lack of input validation in the system hook push queue through the web hook component, resulting in remote code execution.
Recommendations For Gitlab Community Edition version 10.3, consider disabling the web hook component until a patch is available to prevent remote code execution. Restrict access to the system hook push queue to minimize the risk of exploitation.

Correção

RCE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-0916
DSA-4145-1

Produtos afetados

Gitlab
Gitlab Ce/Ee