CVE-2017-0921

HIGH

GitLab <10.1.6-10.3.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0107
EPSS Percentile 60.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-640
Status published
Products (1)
gitlab/gitlab < 10.1.6 (2 CPE variants)
Published Jul 03, 2018
Tracked Since Feb 18, 2026