Beveiligingsadvies

CVE-2017-0921

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-07-03 21:00:00
Laatst bijgewerkt 2024-09-17 00:40:46
Toegewezen door hackerone
CVSS-score geen score
Status PUBLISHED

Beschrijving

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.