Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48fw-3qmc-rmp7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

EPSS

Процентиль: 37%
0.00161
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
nvd
около 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
debian
около 5 лет назад

Information about the starred projects for private user profiles was e ...

EPSS

Процентиль: 37%
0.00161
Низкий

Дефекты

CWE-200