HIGH
CVE-2017-0925
CVSS
7.2
Description
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Summary dbcve.org
GitLab Enterprise Edition 10.1.0 contains an API endpoint for project service integrations that returns plaintext passwords in API responses instead of masking or redacting them, allowing authenticated users to retrieve sensitive credentials.
Mitigation
Upgrade GitLab to the patched version that properly redacts credentials in API responses. Audit and rotate any credentials that may have been exposed.
Weakness (CWE)
CWE-522
Insufficiently Protected Credentials
CWE-319
Cleartext Transmission
EPSS Score
0.87%
Probability of exploitation in next 30 days
57.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.