CVE-2017-11437

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/08/2017
Last modified:
20/04/2025

Description

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:8.5.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.3:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.4:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.5:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.6:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.7:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.8:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.9:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.10:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.11:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.12:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.5.13:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:8.6.0:*:*:*:enterprise:*:*:*