MEDIUM

CVE-2017-0927

Gitlab GitLab 2018-03-21 CVSS v3.0
CVSS
6.5

Description

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.

Summary dbcve.org

GitLab Community Edition 10.3 contains a broken access control vulnerability in the deployment keys component. Guest users, who should have minimal read-only access to public projects, can improperly use deployment keys that should be restricted to higher-privileged users. This allows unauthorized access to repositories via deployment keys.

Mitigation

Upgrade GitLab to version 10.4 or later, which contains the fix for proper authorization checks on deployment keys. If immediate upgrade is not possible, review and restrict guest user permissions and consider disabling deployment keys until the patch can be applied.

Weakness (CWE)

CWE-285 Improper Authorization
CWE-863 Incorrect Authorization

EPSS Score

0.79%
Probability of exploitation in next 30 days
54.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE