Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c63c-249m-g37m

Опубликовано: 02 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

EPSS

Процентиль: 44%
0.00216
Низкий

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
nvd
больше 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
debian
больше 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

EPSS

Процентиль: 44%
0.00216
Низкий

7.5 High

CVSS3

Дефекты

CWE-863