Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xwq-3g46-4j22

Опубликовано: 29 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

EPSS

Процентиль: 31%
0.00119
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
nvd
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
debian
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

EPSS

Процентиль: 31%
0.00119
Низкий

8.8 High

CVSS3

Дефекты

CWE-352