Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32w9-cgpf-p2wf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

EPSS

Процентиль: 34%
0.00412
Низкий

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 2.2
ubuntu
почти 5 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
nvd
почти 5 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
debian
почти 5 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7 ...

EPSS

Процентиль: 34%
0.00412
Низкий

Дефекты

CWE-306