Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32w9-cgpf-p2wf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

EPSS

Процентиль: 32%
0.00124
Низкий

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 2.2
ubuntu
больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
nvd
больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
debian
больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7 ...

EPSS

Процентиль: 32%
0.00124
Низкий

Дефекты

CWE-306