Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwjh-rrw3-f8rp

Опубликовано: 14 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

EPSS

Процентиль: 1%
0.00012
Низкий

3.1 Low

CVSS3

Дефекты

CWE-708

Связанные уязвимости

CVSS3: 3.1
ubuntu
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
nvd
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
debian
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
fstec
7 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с неправильным присвоением права собственности, позволяющая нарушителю провести атаки на домены из-за возможности создания группы с именем, совпадающим с уникальным доменом Pages

EPSS

Процентиль: 1%
0.00012
Низкий

3.1 Low

CVSS3

Дефекты

CWE-708