CVE Vulnerabilities

CVE-2017-0925

Insufficiently Protected Credentials

Published: Mar 21, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

Weakness 

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software 

Name Vendor Start Version End Version
Gitlab Gitlab 8.0.0 (including) 9.5.10 (including)
Gitlab Gitlab 10.0.0 (including) 10.1.5 (including)
Gitlab Gitlab 10.2.0 (including) 10.2.5 (including)
Gitlab Gitlab 10.3.0 (including) 10.3.3 (including)
Gitlab Ubuntu artful *
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *
Gitlab Ubuntu xenial *

Potential Mitigations 

References