PT-2018-5143 · Gitlab · Gitlab Ce/Ee+1

Published

2018-03-18

·

Updated

2019-10-09

·

CVE-2017-0916

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitlab Community Edition version 10.3
Description The issue is related to a lack of input validation in the system hook push queue through the web hook component, resulting in remote code execution.
Recommendations For Gitlab Community Edition version 10.3, consider disabling the web hook component until a patch is available to prevent remote code execution. Restrict access to the system hook push queue to minimize the risk of exploitation.

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0916
DSA-4145-1

Affected Products

Gitlab
Gitlab Ce/Ee