Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p32w-wm8h-w433

Опубликовано: 29 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An information disclosure issue in GitLab CE/EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

An information disclosure issue in GitLab CE/EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

EPSS

Процентиль: 20%
0.00065
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-282

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
nvd
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
debian
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

EPSS

Процентиль: 20%
0.00065
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-282