MEDIUM

CVE-2017-11437

Gitlab GitLab 2017-08-02 CVSS v3.0
CVSS
6.5

Description

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

Summary dbcve.org

This is an improper authorization vulnerability in GitLab EE where an authenticated user with project creation permissions can exploit the repository mirroring feature to read repositories belonging to other users they shouldn't have access to.

Mitigation

Upgrade GitLab EE to version 8.17.7, 9.0.11, 9.1.8, 9.2.8, 9.3.8 or later to patch this vulnerability.

Weakness (CWE)

CWE-732 Incorrect Permission Assignment

EPSS Score

0.79%
Probability of exploitation in next 30 days
54.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE