Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r38-jrwh-8grw

Опубликовано: 12 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

EPSS

Процентиль: 63%
0.00456
Низкий

8.5 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
nvd
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
debian
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

EPSS

Процентиль: 63%
0.00456
Низкий

8.5 High

CVSS3

Дефекты

CWE-362