Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6955-m4p2-35rh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

EPSS

Процентиль: 40%
0.00181
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.8
ubuntu
больше 5 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
nvd
больше 5 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
debian
больше 5 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access C ...

EPSS

Процентиль: 40%
0.00181
Низкий

Дефекты

CWE-200