CVE-2017-12426: GitLab
High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
Affected products
- GitLab GitLab: up to and including 8.17.7; version 9.0.0 only; version 9.0.1 only; version 9.0.2 only; version 9.0.3 only; version 9.0.4 only; …
Published 2017-08-14. Last modified 2026-06-17.