CVE Published: 22/03/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: hackerone |
Vendor: GitLab |
Product: GitLab Community and Enterprise Editions Status : PUBLISHED
CVE-2017-0920 Description
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.