CVE-2017-0920: Medium severity gitlab vulnerability
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0920?
CVE-2017-0920 has a severity rating that indicates a significant risk due to authorization bypass allowing project enumeration.
How do I fix CVE-2017-0920?
To fix CVE-2017-0920, upgrade your GitLab installation to versions 10.1.6, 10.2.6, or 10.3.4 and above.
Who is affected by CVE-2017-0920?
CVE-2017-0920 affects users of GitLab Community and Enterprise Editions prior to versions 10.1.6, 10.2.6, and 10.3.4.
What type of vulnerability is CVE-2017-0920?
CVE-2017-0920 is classified as an authorization bypass vulnerability.
Can CVE-2017-0920 allow unauthorized access to project information?
Yes, CVE-2017-0920 allows attackers to see the names and namespaces of all projects on a GitLab instance without proper authorization.