GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.
2018-07-03T21:29:00.340
2024-11-21T03:03:54.147
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 10.1.6 | Yes |
Application | gitlab | gitlab | < 10.1.6 | Yes |
Application | gitlab | gitlab | < 10.2.6 | Yes |
Application | gitlab | gitlab | < 10.2.6 | Yes |
Application | gitlab | gitlab | < 10.3.4 | Yes |
Application | gitlab | gitlab | < 10.3.4 | Yes |