CVE-2017-0924: GitLab

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.

Affected products

  • GitLab GitLab: from 9.0.0, up to and including 9.5.10; from 10.0.0, up to and including 10.1.5; from 10.2.0, up to and including 10.2.5; from 10.3.0, up to and including 10.3.3

Published 2018-03-21. Last modified 2026-06-17.