Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0919

Опубликовано: 03 июл. 2018
Источник: debian
EPSS Низкий

Описание

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed10.5.5+dfsg-1package

Примечания

  • https://hackerone.com/reports/301137

  • Fixed in 10.1.6, 10.2.6, and 10.3.4

EPSS

Процентиль: 19%
0.0006
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
nvd
почти 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
github
около 3 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

EPSS

Процентиль: 19%
0.0006
Низкий