CVE-2017-11437: GitLab

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

Affected products

  • GitLab GitLab: version 8.5.0 only; version 8.5.1 only; version 8.5.2 only; version 8.5.3 only; version 8.5.4 only; version 8.5.5 only; …

Published 2017-08-02. Last modified 2026-06-17.