Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpgr-mg9w-x2hm

Опубликовано: 29 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

EPSS

Процентиль: 98%
0.53596
Средний

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 10
ubuntu
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
nvd
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
debian
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 10
fstec
больше 3 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками механизма авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 98%
0.53596
Средний

9.8 Critical

CVSS3

Дефекты

CWE-863