CVE-2017-12426
HIGH 8.8EPSS 3.5%
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 3.54% chance of exploitation in the next 30 days, 88th percentile
- Published
- 2017-08-14
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- sm-paul-schuette/CVE-2017-124260★ · 2017-08-14