Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j48w-jfc5-3885

Опубликовано: 10 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

EPSS

Процентиль: 39%
0.00178
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 4.3
nvd
около 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 4.3
debian
около 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

EPSS

Процентиль: 39%
0.00178
Низкий

5.3 Medium

CVSS3