MEDIUM
CVE-2017-11438
CVSS
6.3
Description
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.
Summary dbcve.org
GitLab CE/EE versions before 9.0.11, 9.1.8, and 9.2.8 contain an authorization flaw where an authenticated user with group creation permissions can add themselves to any project residing within a subgroup, bypassing intended access controls.
Mitigation
Upgrade GitLab to version 9.0.11, 9.1.8, 9.2.8 or later to receive the patch. Alternatively, restrict group creation permissions until the upgrade can be performed.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.62%
Probability of exploitation in next 30 days
48.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.