CVE-2017-0920: GitLab
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Affected products
- GitLab GitLab: after 8.8.0, up to and including 10.1.5; from 8.8.0, up to and including 10.1.5; after 10.2.0, up to and including 10.2.5; from 10.2.0, up to and including 10.2.5; after 10.3.0, up to and including 10.3.3; from 10.3.0, up to and including 10.3.3
Published 2018-03-22. Last modified 2026-06-17.