Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4ff-rc49-g8hc

Опубликовано: 16 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

EPSS

Процентиль: 26%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
nvd
около 2 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
debian
около 2 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...

CVSS3: 3.5
fstec
около 2 лет назад

Уязвимость функции Merge request approvals программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-639