CVE-2017-8446: Improper Privilege Management
(updated )
The Reporting feature in X-Pack has an impersonation vulnerability. A user with the reporting_user
role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
References
Detect and mitigate CVE-2017-8446 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →