PT-2018-5145 · Gitlab · Gitlab Ce/Ee+1

Jobert

·

Published

2018-03-18

·

Updated

2019-10-09

·

CVE-2017-0918

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitlab Community Edition version 10.3
Description The issue is related to a path traversal problem in the GitLab CI runner component, which results in remote code execution.
Recommendations For Gitlab Community Edition version 10.3, update to a version that fixes the path traversal issue in the GitLab CI runner component to prevent remote code execution.

Fix

RCE

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0918
DSA-4145-1

Affected Products

Gitlab
Gitlab Ce/Ee