Описание
The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.
The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-35236
- https://github.com/amazeeio/lagoon/commit/1140289bf9fa98b8602ab4662ae867b210d8476b
- https://github.com/amazeeio/lagoon/compare/v1.12.2...v1.12.3
- https://github.com/amazeeio/lagoon/tree/master/services/webhook-handler
- https://github.com/amazeeio/lagoon/tree/master/services/webhooks2tasks
Связанные уязвимости
CVSS3: 5.3
nvd
около 5 лет назад
The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.