VulnerabilityModified
CVE-2017-0927
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
MEDIUM 6.5EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-863
- Affected
- gitlab/gitlab
- Source
- support@hackerone.com
References
- https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/37594Issue Tracking, Third Party Advisory
- https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/37594Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.