CVE-2017-0927
published 2018-03-21CVE-2017-0927: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
0.82%
53.5th percentile
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 10.5.5+dfsg-1 (sid) | gitlab 10.5.5+dfsg-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | 10.0.0 – 10.1.5 | — |
| gitlab | gitlab | 10.2.0 – 10.2.5 | — |
| gitlab | gitlab | 10.3.0 – 10.3.3 | — |
| gitlab | gitlab | 8.16.0 – 9.5.10 | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
| gitlab | gitlab_community_and_enterprise_editions | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9j4q-pv73-3355: Gitlab Community Edition version 10
ghsa_unreviewed·2022-05-13
CVE-2017-0927 [MEDIUM] CWE-863 GHSA-9j4q-pv73-3355: Gitlab Community Edition version 10
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
GitLab
CVE-2017-0927: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use
vendor_gitlab·2018-03-21·CVSS 6.5
CVE-2017-0927 [MEDIUM] CWE-285 CVE-2017-0927: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use
CVE-2017-0927: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
Debian
CVE-2017-0927: gitlab - Gitlab Community Edition version 10.3 is vulnerable to an improper authorization...
vendor_debian·2017·CVSS 6.5
CVE-2017-0927 [MEDIUM] CVE-2017-0927: gitlab - Gitlab Community Edition version 10.3 is vulnerable to an improper authorization...
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-21
Published