CVE-2017-0921

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
03/07/2018
Last modified:
04/09/2018

Description

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 10.1.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.1.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 10.2.0 (including) 10.2.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.2.0 (including) 10.2.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 10.3.0 (including) 10.3.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.3.0 (including) 10.3.4 (excluding)