Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phq7-q979-hvg6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

EPSS

Процентиль: 29%
0.00101
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 6 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

CVSS3: 4.3
nvd
почти 6 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

CVSS3: 4.3
debian
почти 6 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affe ...

EPSS

Процентиль: 29%
0.00101
Низкий