Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0920

Опубликовано: 22 мар. 2018
Источник: debian
EPSS Низкий

Описание

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed10.5.5+dfsg-1package

Примечания

  • https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/

EPSS

Процентиль: 28%
0.00094
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
nvd
около 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
github
около 3 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

EPSS

Процентиль: 28%
0.00094
Низкий