CVE-2017-0922: GitLab
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
Affected products
- GitLab GitLab: from 9.1.0, up to and including 9.5.10; from 10.0.0, up to and including 10.1.5; from 10.2.0, up to and including 10.2.5; from 10.3.0, up to and including 10.3.3
Published 2018-03-21. Last modified 2026-06-17.