First published: Wed Mar 21 2018(Updated: )
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=9.1.0<=9.5.10 | |
GitLab | >=9.1.0<=9.5.10 | |
GitLab | >=10.0.0<=10.1.5 | |
GitLab | >=10.0.0<=10.1.5 | |
GitLab | >=10.2.0<=10.2.5 | |
GitLab | >=10.2.0<=10.2.5 | |
GitLab | >=10.3.0<=10.3.3 | |
GitLab | >=10.3.0<=10.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0922 has a medium severity rating due to its potential for information disclosure.
CVE-2017-0922 affects GitLab versions from 9.1.0 to 10.3.3.
To fix CVE-2017-0922, update your GitLab installation to version 10.3.4 or later.
CVE-2017-0922 is an authorization bypass vulnerability within the GitLab Projects::BoardsController.
Attackers can exploit CVE-2017-0922 to gain unauthorized access to board objects and disclose sensitive information.