Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c64-9pw3-wh7p

Опубликовано: 22 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

EPSS

Процентиль: 25%
0.00325
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
nvd
почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
debian
почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

EPSS

Процентиль: 25%
0.00325
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-863