Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgg5-84cv-fc3c

Опубликовано: 12 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

EPSS

Процентиль: 100%
0.93578
Критический

10 Critical

CVSS3

Дефекты

CWE-284
CWE-640

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
nvd
около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
debian
около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 10
fstec
около 2 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, вызванная возможностью отправки письма с кодом для сброса пароля на неподтверждённые email-адреса, позволяющая нарушителю получить несанкционированный доступ к учётной записи произвольного пользователя

EPSS

Процентиль: 100%
0.93578
Критический

10 Critical

CVSS3

Дефекты

CWE-284
CWE-640