Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wmm-qgmm-95gm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

CVSS3: 6.5
nvd
больше 5 лет назад

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

CVSS3: 6.5
debian
больше 5 лет назад

Membership changes are not reflected in ToDo subscriptions in GitLab v ...

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-200