CVE-2017-0920
published 2018-03-22CVE-2017-0920: GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.90%
56.1th percentile
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 10.5.5+dfsg-1 (sid) | gitlab 10.5.5+dfsg-1 (sid) |
| gitlab | gitlab | <= 10.1.5 | — |
| gitlab | gitlab | <= 10.2.5 | — |
| gitlab | gitlab | <= 10.3.3 | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | 10.2.0 – 10.2.5 | — |
| gitlab | gitlab | 10.3.0 – 10.3.3 | — |
| gitlab | gitlab | 8.8.0 – 10.1.5 | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2017-0920: GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeReque
vendor_gitlab·2018-03-22·CVSS 4.3
CVE-2017-0920 [MEDIUM] CWE-639 CVE-2017-0920: GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeReque
CVE-2017-0920: GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Debian
CVE-2017-0920: gitlab - GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are v...
vendor_debian·2017·CVSS 4.3
CVE-2017-0920 [MEDIUM] CVE-2017-0920: gitlab - GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are v...
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
GHSA
GHSA-vg8q-6f88-6vrh: GitLab Community and Enterprise Editions before 10
ghsa_unreviewed·2022-05-13
CVE-2017-0920 [MEDIUM] CWE-863 GHSA-vg8q-6f88-6vrh: GitLab Community and Enterprise Editions before 10
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
No detection rules found.
No public exploits indexed.
2018-03-22
Published