Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm4r-vwvw-vj67

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

EPSS

Процентиль: 5%
0.00019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
nvd
4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
debian
4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
fstec
5 месяцев назад

Уязвимость интерфейса GraphQL API программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации

EPSS

Процентиль: 5%
0.00019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201