Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-39872

Опубликовано: 05 окт. 2021
Источник: debian
EPSS Низкий

Описание

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed15.10.8+ds1-2package

EPSS

Процентиль: 44%
0.00215
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

CVSS3: 6.5
nvd
почти 4 года назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

github
около 3 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS

Процентиль: 44%
0.00215
Низкий