Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r375-6xr6-qqjq

Опубликовано: 10 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

EPSS

Процентиль: 1%
0.00013
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.4
ubuntu
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
nvd
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
debian
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.4
fstec
4 месяца назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 1%
0.00013
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1021