Total vulnerabilities in the database
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
Software | From | Fixed in |
---|---|---|
gitlab / gitlab | 10.3.0 | 10.3.3.x |
gitlab / gitlab | 10.0.0 | 10.1.5.x |
gitlab / gitlab | 10.2.0 | 10.2.5.x |
gitlab / gitlab | 9.4.0 | 9.5.10.x |