Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73p8-f56m-692w

Опубликовано: 27 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

EPSS

Процентиль: 14%
0.00046
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
12 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
debian
12 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.3
fstec
12 месяцев назад

Уязвимость механизма аутентификации Single sign-on (SSO) веб-интерфейса GitLab Duo Chat программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 14%
0.00046
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862