HIGH

CVE-2017-0925

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
7.2

Description

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

Summary dbcve.org

GitLab Enterprise Edition 10.1.0 contains an API endpoint for project service integrations that returns plaintext passwords in API responses instead of masking or redacting them, allowing authenticated users to retrieve sensitive credentials.

Mitigation

Upgrade GitLab to the patched version that properly redacts credentials in API responses. Audit and rotate any credentials that may have been exposed.

Weakness (CWE)

CWE-522 Insufficiently Protected Credentials
CWE-319 Cleartext Transmission

EPSS Score

0.87%
Probability of exploitation in next 30 days
57.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE