Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq9r-r987-7r36

Опубликовано: 05 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

EPSS

Процентиль: 30%
0.00105
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.1
ubuntu
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 3.1
nvd
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 3.1
debian
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction ...

EPSS

Процентиль: 30%
0.00105
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863