Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5g3-c7f9-3hcj

Опубликовано: 11 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with admin_compliance_framework custom role may have been able to modify the URL for a group namespace.

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with admin_compliance_framework custom role may have been able to modify the URL for a group namespace.

EPSS

Процентиль: 2%
0.00015
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.9
ubuntu
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
nvd
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
debian
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.9
fstec
12 месяцев назад

Уязвимость функции admin_compliance_framework компонента Group Namespace URL Handler программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю изменить URL-адрес группы

EPSS

Процентиль: 2%
0.00015
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284