Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5h7x-5p3m-j723

Опубликовано: 06 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious maintainer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious maintainer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

EPSS

Процентиль: 89%
0.04617
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.5
ubuntu
больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
nvd
больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
debian
больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

EPSS

Процентиль: 89%
0.04617
Низкий

5.5 Medium

CVSS3