Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w9g-7w46-w7h4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

EPSS

Процентиль: 48%
0.00245
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-732

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
nvd
больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
debian
больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure di ...

EPSS

Процентиль: 48%
0.00245
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-732