HIGH

CVE-2017-0919

Gitlab GitLab 2018-07-03 CVSS v3.0
CVSS
7.5

Description

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab's import component that allows an authenticated attacker to perform operations under groups where they previously lacked authorization. The flaw enables privilege escalation within the GitLab platform.

Mitigation

Upgrade GitLab to version 10.1.6, 10.2.6, 10.3.4 or later to remediate this authorization bypass in the import component.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE