CVE-2017-0919: High severity gitlab vulnerability
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0919?
CVE-2017-0919 has a medium severity rating due to its potential to allow unauthorized operations within GitLab groups.
How do I fix CVE-2017-0919?
To fix CVE-2017-0919, upgrade your GitLab Community or Enterprise Edition to version 10.1.6, 10.2.6, or 10.3.4 or later.
What type of vulnerability is identified in CVE-2017-0919?
CVE-2017-0919 is an authorization bypass vulnerability that affects the GitLab import component.
What software is affected by CVE-2017-0919?
CVE-2017-0919 affects GitLab Community and Enterprise Editions prior to versions 10.1.6, 10.2.6, and 10.3.4.
How was CVE-2017-0919 discovered?
CVE-2017-0919 was reported through a security vulnerability report that highlighted the potential for unauthorized access.