SB2018080312 - Cross-site scripting in GitLab, Gitlab Community Edition
Published: August 3, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2018-12605)
The vulnerability allows a remote authenticated user to read and manipulate data.
An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.
Remediation
Install update from vendor's website.