CVE-2017-0927

Severity
6.5MEDIUM
EPSS
0.1%
top 73.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 8.10.6 - 10.1.5 Fixed in 10.1.6+2
NVDgitlab/gitlab8.16.09.5.10+3

🔴Vulnerability Details

2
GHSA
GHSA-9j4q-pv73-3355: Gitlab Community Edition version 102022-05-13
CVEList
CVE-2017-0927: Gitlab Community Edition version 102018-03-21

📋Vendor Advisories

2
GitLab
CVE-2017-0927: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use2018-03-21
Debian
CVE-2017-0927: gitlab - Gitlab Community Edition version 10.3 is vulnerable to an improper authorization...2017
CVE-2017-0927 (MEDIUM CVSS 6.5) | Gitlab Community Edition version 10 | cvebase.io