Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-797c-p7mm-pf4h

Опубликовано: 12 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

EPSS

Процентиль: 8%
0.00034
Низкий

3.5 Low

CVSS3

Дефекты

CWE-345
CWE-347

Связанные уязвимости

CVSS3: 3.5
ubuntu
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
nvd
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
debian
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.5
fstec
больше 1 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю изменить метаданные подписанных коммитов

EPSS

Процентиль: 8%
0.00034
Низкий

3.5 Low

CVSS3

Дефекты

CWE-345
CWE-347