CVE-2017-0921
03.07.2018, 21:29
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 𝑥 < 10.1.6 |
| gitlab | gitlab | 𝑥 < 10.1.6 |
| gitlab | gitlab | 10.2.0 ≤ 𝑥 < 10.2.6 |
| gitlab | gitlab | 10.2.0 ≤ 𝑥 < 10.2.6 |
| gitlab | gitlab | 10.3.0 ≤ 𝑥 < 10.3.4 |
| gitlab | gitlab | 10.3.0 ≤ 𝑥 < 10.3.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration