Vulnerability CVE-2017-11438


Published: 2017-08-02   Modified: 2017-08-03

Description:
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

Type:

CWE-269

(Improper Privilege Management)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Gitlab -> Gitlab 

 References:
https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/

Copyright 2026, cxsecurity.com

 

Back to Top