about.gitlab.comConfirmation
https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released CVE-2017-0922
HIGH
Record summary
CVE-2017-0922 has a selected CVSS score of 7.5 (high).
Description
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLab Community and Enterprise EditionsBrowse GitLab / GitLab Community and Enterprise Editions | CVE List | 9.1.0 - 10.1.5 Fixed in 10.1.6 | affected |
| 10.2.0 - 10.2.5 Fixed in 10.2.6 | affected | ||
| 10.3.0 - 10.3.3 Fixed in 10.3.4 | affected |
References
3hackerone.com
https://hackerone.com/reports/301123 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0922