Unrated severityNVD Advisory· Published Mar 21, 2018· Updated Aug 5, 2024
CVE-2017-0914
CVE-2017-0914
Description
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
Affected products
1- Range: 9.1.0 - 10.1.5 Fixed in 10.1.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/mitrex_refsource_CONFIRM
- hackerone.com/reports/298176mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.