Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfcp-rjv7-385m

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

EPSS

Процентиль: 3%
0.00016
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
nvd
2 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
debian
2 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions f ...

CVSS3: 4.3
fstec
2 месяца назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с раскрытием информации при передаче данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 3%
0.00016
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201