CVE-2017-0916: Debian Linux
Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
Affected products
- Debian Debian Linux: version 9.0 only
- GitLab GitLab: from 8.8.0, up to and including 10.1.5; from 10.2.0, up to and including 10.2.5; from 10.3.0, up to and including 10.3.3
Published 2018-03-21. Last modified 2026-06-17.