Upstream information

CVE-2017-0882 at MITRE

Description

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.00
Vector AV:N/AC:L/Au:S/C:P/I:N/A:N
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 6.3
Vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Access Vector Network
Access Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
SUSE Bugzilla entry: 1030599 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.