Record summary

CVE-2017-0922 has a selected CVSS score of 7.5 (high).

Description

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

GitLab Community and Enterprise Editions

Browse GitLab / GitLab Community and Enterprise Editions
CVE List9.1.0 - 10.1.5 Fixed in 10.1.6affected
10.2.0 - 10.2.5 Fixed in 10.2.6affected
10.3.0 - 10.3.3 Fixed in 10.3.4affected

References

3