CVE-2017-0925: Debian Linux

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

Affected products

  • Debian Debian Linux: version 9.0 only
  • GitLab GitLab: from 8.0.0, up to and including 9.5.10; from 10.0.0, up to and including 10.1.5; from 10.2.0, up to and including 10.2.5; from 10.3.0, up to and including 10.3.3

Published 2018-03-21. Last modified 2026-06-17.