Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rppq-5vq8-crrp

Опубликовано: 24 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

EPSS

Процентиль: 4%
0.00021
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1220

Связанные уязвимости

CVSS3: 6.4
ubuntu
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

CVSS3: 6.4
nvd
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

CVSS3: 6.4
debian
7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

EPSS

Процентиль: 4%
0.00021
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1220