MEDIUM

CVE-2017-11438

Gitlab GitLab 2017-08-02 CVSS v3.0
CVSS
6.3

Description

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

Summary dbcve.org

GitLab CE/EE versions before 9.0.11, 9.1.8, and 9.2.8 contain an authorization flaw where an authenticated user with group creation permissions can add themselves to any project residing within a subgroup, bypassing intended access controls.

Mitigation

Upgrade GitLab to version 9.0.11, 9.1.8, 9.2.8 or later to receive the patch. Alternatively, restrict group creation permissions until the upgrade can be performed.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.62%
Probability of exploitation in next 30 days
48.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE