CVE-2017-0882: GitLab

Medium severity, CVSS 6.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

Affected products

  • GitLab GitLab: version 8.2.0 only; version 8.2.1 only; version 8.2.2 only; version 8.2.3 only; version 8.2.4 only; version 8.2.5 only; …

Published 2017-03-28. Last modified 2026-06-17.