Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px7v-hx94-8wmf

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 0

Описание

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.

EPSS

Процентиль: 17%
0.00249
Низкий

0 Low

CVSS3

Дефекты

CWE-350

Связанные уязвимости

nvd
3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.

CVSS3: 3.1
fstec
3 месяца назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с зависимостью критичных действий от обратного DNS-решения, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 17%
0.00249
Низкий

0 Low

CVSS3

Дефекты

CWE-350