about.gitlab.comConfirmation
https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released CVE-2017-0920
MEDIUM
Record summary
CVE-2017-0920 has a selected CVSS score of 4.3 (medium).
Description
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLab Community and Enterprise EditionsBrowse GitLab / GitLab Community and Enterprise Editions | CVE List | Versions before 10.1.6, 10.2.6, and 10.3.4 | affected |
References
4hackerone.com
https://hackerone.com/reports/301336 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0920 DSA-4206Vendor advisory
https://www.debian.org/security/2018/dsa-4206