PT-2018-5152 · Gitlab · Gitlab Ce/Ee+1
Publicado
2018-03-18
·
Atualizado
2019-10-09
·
CVE-2017-0925
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gitlab Enterprise Edition version 10.1.0
Description
The issue concerns an insufficiently protected credential problem in the "project service integration API endpoint" that results in the disclosure of plaintext password information.
Recommendations
For Gitlab Enterprise Edition version 10.1.0, consider disabling access to the project service integration API endpoint until a fix is available to prevent the disclosure of plaintext password information.
Correção
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gitlab
Gitlab Ce/Ee