Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prp4-5w2g-8v2c

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

EPSS

Процентиль: 48%
0.00612
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.9
nvd
12 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

EPSS

Процентиль: 48%
0.00612
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-502