PT-2018-5152 · Gitlab · Gitlab Ce/Ee+1
Published
2018-03-18
·
Updated
2019-10-09
·
CVE-2017-0925
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gitlab Enterprise Edition version 10.1.0
Description
The issue concerns an insufficiently protected credential problem in the "project service integration API endpoint" that results in the disclosure of plaintext password information.
Recommendations
For Gitlab Enterprise Edition version 10.1.0, consider disabling access to the project service integration API endpoint until a fix is available to prevent the disclosure of plaintext password information.
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee