Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0921

Опубликовано: 03 июл. 2018
Источник: debian
EPSS Низкий

Описание

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed10.7.5+dfsg-1experimentalpackage
gitlabfixed10.7.7+dfsg-2package

Примечания

  • https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/

EPSS

Процентиль: 27%
0.00089
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
nvd
почти 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
github
около 3 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

EPSS

Процентиль: 27%
0.00089
Низкий