~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
Candidate: CVE-2017-11438
PublicDate: 2017-08-02
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11438
 https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/
Description:
 GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11,
 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group
 to add themselves to any project that is inside a subgroup.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_gitlab:
upstream_gitlab: released (9.3.8, 9.2.8, 9.1.8, 9.0.11, 8.17.7)
precise/esm_gitlab: DNE
trusty_gitlab: DNE
vivid/ubuntu-core_gitlab: DNE
xenial_gitlab: needed
zesty_gitlab: needed
devel_gitlab: needed