CVE-2017-0926

Severity
8.8HIGH
EPSS
0.3%
top 45.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgitlab/gitlab8.8.09.5.10+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-64x3-qr9c-w6jw: Gitlab Community Edition version 102022-05-13
CVEList
CVE-2017-0926: Gitlab Community Edition version 102018-03-21

💥Exploits & PoCs

1
Exploit-DB
Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory2017-03-27

📋Vendor Advisories

2
GitLab
CVE-2017-0926: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user l2018-03-21
Debian
CVE-2017-0926: gitlab - Gitlab Community Edition version 10.3 is vulnerable to an improper authorization...2017
CVE-2017-0926 (HIGH CVSS 8.8) | Gitlab Community Edition version 10 | cvebase.io