Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84m5-rqxq-483p

Опубликовано: 26 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

EPSS

Процентиль: 88%
0.03809
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
nvd
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
debian
больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions af ...

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость компонента API PUT Request Handler программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю выполнить произвольные запросы API PUT

EPSS

Процентиль: 88%
0.03809
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80