CVE-2017-0882

MEDIUM

GitLab <8.15.8-8.17.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97157
Exploit, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab-ce/issues/29661
Release Notes, Vendor Advisory x_refsource_misc
https://about.gitlab.com/2017/03/20/gitlab-8-dot-17-dot-4-security-release/

Scores

CVSS v3 6.3
EPSS 0.0018
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-639 CWE-200
Status published
Products (50)
gitlab/gitlab 8.2.0
gitlab/gitlab 8.2.1
gitlab/gitlab 8.2.2
gitlab/gitlab 8.2.3
gitlab/gitlab 8.2.4
gitlab/gitlab 8.2.5
gitlab/gitlab 8.3.0
gitlab/gitlab 8.3.8
gitlab/gitlab 8.3.9
gitlab/gitlab 8.4.0
... and 40 more
Published Mar 28, 2017
Tracked Since Feb 18, 2026