CVE-2017-0925
HIGHGitlab EE <10.1.0 - Info Disclosure
Title source: llmDescription
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Scores
CVSS v3
7.2
EPSS
0.0010
EPSS Percentile
28.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-319
CWE-522
Status
published
Affected Products (3)
gitlab/gitlab
< 9.5.10
gitlab/gitlab
< 9.5.10
debian/debian_linux
Timeline
Published
Mar 21, 2018
Tracked Since
Feb 18, 2026