CVE-2017-0882
28.03.2017, 02:59
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 8.2.0 |
gitlab | gitlab | 8.2.1 |
gitlab | gitlab | 8.2.2 |
gitlab | gitlab | 8.2.3 |
gitlab | gitlab | 8.2.4 |
gitlab | gitlab | 8.2.5 |
gitlab | gitlab | 8.3.0 |
gitlab | gitlab | 8.3.8 |
gitlab | gitlab | 8.3.9 |
gitlab | gitlab | 8.4.0 |
gitlab | gitlab | 8.4.9 |
gitlab | gitlab | 8.4.10 |
gitlab | gitlab | 8.5.0 |
gitlab | gitlab | 8.5.11 |
gitlab | gitlab | 8.5.12 |
gitlab | gitlab | 8.6.0 |
gitlab | gitlab | 8.6.7 |
gitlab | gitlab | 8.6.8 |
gitlab | gitlab | 8.7.0 |
gitlab | gitlab | 8.7.1 |
gitlab | gitlab | 8.10.0 |
gitlab | gitlab | 8.10.12 |
gitlab | gitlab | 8.10.13 |
gitlab | gitlab | 8.11.0 |
gitlab | gitlab | 8.11.9 |
gitlab | gitlab | 8.11.10 |
gitlab | gitlab | 8.12.0 |
gitlab | gitlab | 8.12.7 |
gitlab | gitlab | 8.12.8 |
gitlab | gitlab | 8.13.0 |
gitlab | gitlab | 8.13.2 |
gitlab | gitlab | 8.13.3 |
gitlab | gitlab | 8.14.0 |
gitlab | gitlab | 8.14.1 |
gitlab | gitlab | 8.14.2 |
gitlab | gitlab | 8.14.3 |
gitlab | gitlab | 8.14.4 |
gitlab | gitlab | 8.14.5 |
gitlab | gitlab | 8.14.6 |
gitlab | gitlab | 8.15.0 |
gitlab | gitlab | 8.15.1 |
gitlab | gitlab | 8.15.2 |
gitlab | gitlab | 8.15.3 |
gitlab | gitlab | 8.15.4 |
gitlab | gitlab | 8.15.5 |
gitlab | gitlab | 8.15.6 |
gitlab | gitlab | 8.15.7 |
gitlab | gitlab | 8.16.0 |
gitlab | gitlab | 8.16.1 |
gitlab | gitlab | 8.16.2 |
gitlab | gitlab | 8.16.3 |
gitlab | gitlab | 8.16.4 |
gitlab | gitlab | 8.16.5 |
gitlab | gitlab | 8.16.6 |
gitlab | gitlab | 8.16.7 |
gitlab | gitlab | 8.17.0 |
gitlab | gitlab | 8.17.1 |
gitlab | gitlab | 8.17.2 |
gitlab | gitlab | 8.17.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References