HIGH
CVE-2017-0919
CVSS
7.5
Description
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab's import component that allows an authenticated attacker to perform operations under groups where they previously lacked authorization. The flaw enables privilege escalation within the GitLab platform.
Mitigation
Upgrade GitLab to version 10.1.6, 10.2.6, 10.3.4 or later to remediate this authorization bypass in the import component.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.7th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.