CVE-2017-0914: SQL Injection
Published Mar 21, 2018
·Updated
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
Affected Software
8 affected components
GitLab GitLab>=9.4.0<=9.5.10
GitLab GitLab>=9.4.0<=9.5.10
GitLab GitLab>=10.0.0<=10.1.5
GitLab GitLab>=10.0.0<=10.1.5
GitLab GitLab>=10.2.0<=10.2.5
GitLab GitLab>=10.2.0<=10.2.5
GitLab GitLab>=10.3.0<=10.3.3
GitLab GitLab>=10.3.0<=10.3.3
Event History
Mar 21, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0914?
CVE-2017-0914 is classified as a high severity vulnerability due to its potential for SQL injection and data disclosure.
2
How do I fix CVE-2017-0914?
To fix CVE-2017-0914, upgrade GitLab to version 10.3.4 or later.
3
What software versions are affected by CVE-2017-0914?
CVE-2017-0914 affects GitLab Community and Enterprise Editions from 9.4.0 to 10.2.5.
4
What type of vulnerability is CVE-2017-0914?
CVE-2017-0914 is a SQL injection vulnerability found in the MilestoneFinder component.
5
What could be the impact of exploiting CVE-2017-0914?
Exploiting CVE-2017-0914 could lead to unauthorized disclosure of all data in a GitLab instance's database.