Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2826-9vpv-crx3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

EPSS

Процентиль: 38%
0.00163
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

CVSS3: 6.5
nvd
почти 6 лет назад

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

CVSS3: 6.5
debian
почти 6 лет назад

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4 ...

EPSS

Процентиль: 38%
0.00163
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532