Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-339r-94ww-rwcq

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

EPSS

Процентиль: 40%
0.00187
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-732

Связанные уязвимости

CVSS3: 2.7
ubuntu
больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
nvd
больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
debian
больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions ...

EPSS

Процентиль: 40%
0.00187
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-732