CVE-2017-0919

NameCVE-2017-0919
DescriptionGitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gitlabunknown(unstable)10.5.5+dfsg-1

Notes

https://hackerone.com/reports/301137
Fixed in 10.1.6, 10.2.6, and 10.3.4

Search for package or bug name: Reporting problems