Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh9c-h28h-pf65

Опубликовано: 04 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

EPSS

Процентиль: 19%
0.00059
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201
CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
debian
больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

EPSS

Процентиль: 19%
0.00059
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201
CWE-284