Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqcc-25cv-67xr

Опубликовано: 03 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

EPSS

Процентиль: 49%
0.00263
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
nvd
почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
debian
почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 ...

EPSS

Процентиль: 49%
0.00263
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863