Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13011

Опубликовано: 10 мар. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed11.10.8+dfsg-1experimentalpackage
gitlabfixed12.6.8-3package

Примечания

  • https://about.gitlab.com/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/

EPSS

Процентиль: 22%
0.00069
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
nvd
больше 5 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

github
около 3 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

EPSS

Процентиль: 22%
0.00069
Низкий