Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-22186

Опубликовано: 24 мар. 2021
Источник: debian
EPSS Низкий

Описание

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed13.7.8+ds1-1experimentalpackage
gitlabfixed15.10.8+ds1-2package

Примечания

  • https://about.gitlab.com/releases/2021/03/04/security-release-gitlab-13-9-2-released/

EPSS

Процентиль: 38%
0.0017
Низкий

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 5 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

CVSS3: 4.9
nvd
почти 5 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

github
больше 3 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

EPSS

Процентиль: 38%
0.0017
Низкий