CVE-2017-11437

NameCVE-2017-11437
DescriptionGitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gitlab (PTS)sid/contrib13.4.7-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gitlabsource(unstable)(not affected)

Notes

- gitlab <not-affected> (Only affects Enterprise Edition)
https://gitlab.com/gitlab-org/gitlab-ee/issues/2905
https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/

Search for package or bug name: Reporting problems