Vulnerability Description
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 9.1.0, <= 9.5.10 |
Related Weaknesses (CWE)
References
- https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/Vendor Advisory
- https://hackerone.com/reports/301123Permissions Required
- https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/Vendor Advisory
- https://hackerone.com/reports/301123Permissions Required
FAQ
What is CVE-2017-0922?
CVE-2017-0922 is a vulnerability with a CVSS score of 7.5 (HIGH). Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
How severe is CVE-2017-0922?
CVE-2017-0922 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-0922?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.