Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r375-6xr6-qqjq

Опубликовано: 10 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

EPSS

Процентиль: 3%
0.00016
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.4
ubuntu
10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
nvd
10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
debian
10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.4
fstec
10 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 3%
0.00016
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1021