Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc38-g3j7-hgww

Опубликовано: 12 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

EPSS

Процентиль: 49%
0.0026
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
nvd
больше 3 лет назад

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
debian
больше 3 лет назад

It was possible to disclose details of confidential notes created via ...

EPSS

Процентиль: 49%
0.0026
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863