CVE-2017-0922: High severity gitlab vulnerability
Published Mar 21, 2018
·Updated
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
Affected Software
8 affected components
GitLab GitLab>=9.1.0<=9.5.10
GitLab GitLab>=9.1.0<=9.5.10
GitLab GitLab>=10.0.0<=10.1.5
GitLab GitLab>=10.0.0<=10.1.5
GitLab GitLab>=10.2.0<=10.2.5
GitLab GitLab>=10.2.0<=10.2.5
GitLab GitLab>=10.3.0<=10.3.3
GitLab GitLab>=10.3.0<=10.3.3
Event History
Mar 21, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0922?
CVE-2017-0922 has a medium severity rating due to its potential for information disclosure.
2
What versions are affected by CVE-2017-0922?
CVE-2017-0922 affects GitLab versions from 9.1.0 to 10.3.3.
3
How do I fix CVE-2017-0922?
To fix CVE-2017-0922, update your GitLab installation to version 10.3.4 or later.
4
What kind of vulnerability is CVE-2017-0922?
CVE-2017-0922 is an authorization bypass vulnerability within the GitLab Projects::BoardsController.
5
What can attackers achieve with CVE-2017-0922?
Attackers can exploit CVE-2017-0922 to gain unauthorized access to board objects and disclose sensitive information.