CVE-2017-0925
published 2018-03-21CVE-2017-0925: Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint…
PriorityP335high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
0.90%
55.6th percentile
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gitlab | < gitlab 10.5.5+dfsg-1 (sid) | gitlab 10.5.5+dfsg-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | 10.0.0 – 10.1.5 | — |
| gitlab | gitlab | 10.2.0 – 10.2.5 | — |
| gitlab | gitlab | 10.3.0 – 10.3.3 | — |
| gitlab | gitlab | 8.0.0 – 9.5.10 | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwr7-9543-4584: Gitlab Enterprise Edition version 10
ghsa_unreviewed·2022-05-13
CVE-2017-0925 [HIGH] CWE-319 GHSA-fwr7-9543-4584: Gitlab Enterprise Edition version 10
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
OSV
CVE-2017-0925: Gitlab Enterprise Edition version 10
osv·2018-03-21·CVSS 7.2
CVE-2017-0925 [HIGH] CVE-2017-0925: Gitlab Enterprise Edition version 10
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
GitLab
CVE-2017-0925: Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint
vendor_gitlab·2018-03-21·CVSS 7.2
CVE-2017-0925 [HIGH] CWE-522 CVE-2017-0925: Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint
CVE-2017-0925: Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Debian
CVE-2017-0925: gitlab - Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently prot...
vendor_debian·2017·CVSS 7.2
CVE-2017-0925 [HIGH] CVE-2017-0925: gitlab - Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently prot...
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/https://gitlab.com/gitlab-org/gitlab-ee/issues/3847https://www.debian.org/security/2018/dsa-4145https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/https://gitlab.com/gitlab-org/gitlab-ee/issues/3847https://www.debian.org/security/2018/dsa-4145
2018-03-21
Published