CVE-2017-0882

MEDIUM

GitLab <8.15.8-8.17.4 - Info Disclosure

Title source: llm

Description

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

Scores

CVSS v3 6.3
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-639 CWE-200
Status published

Affected Products (50)

gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
... and 35 more

Timeline

Published Mar 28, 2017
Tracked Since Feb 18, 2026