Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcc5-x3g2-xc22

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

EPSS

Процентиль: 40%
0.00186
Низкий

8.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
nvd
больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
debian
больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...

EPSS

Процентиль: 40%
0.00186
Низкий

8.1 High

CVSS3

Дефекты

CWE-613