Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxfq-cc8j-j2pp

Опубликовано: 17 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

EPSS

Процентиль: 94%
0.15514
Средний

8 High

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 3 лет назад

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

CVSS3: 4.8
nvd
около 3 лет назад

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

CVSS3: 4.8
debian
около 3 лет назад

Improper sanitization of branch names in GitLab Runner affecting all v ...

EPSS

Процентиль: 94%
0.15514
Средний

8 High

CVSS3

Дефекты

CWE-77
CWE-78