PT-2018-5152 · Gitlab · Gitlab Ce/Ee+1

Published

2018-03-18

·

Updated

2019-10-09

·

CVE-2017-0925

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitlab Enterprise Edition version 10.1.0
Description The issue concerns an insufficiently protected credential problem in the "project service integration API endpoint" that results in the disclosure of plaintext password information.
Recommendations For Gitlab Enterprise Edition version 10.1.0, consider disabling access to the project service integration API endpoint until a fix is available to prevent the disclosure of plaintext password information.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0925
DSA-4145-1

Affected Products

Gitlab
Gitlab Ce/Ee