GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4...
Vulnerability Description
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-0920
Credits & Attribution
No credits recorded in the NVD database.
References
More from GitLab
View All →Affected Vendor
GitLab
View all reports →