← Back to CVE List

CVE-2017-0920

Published: 2018-03-22T15:29Z
Last Modified: 2024-11-21T03:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt