Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v95j-qhvj-8v9x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS

Процентиль: 44%
0.00215
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

CVSS3: 6.5
nvd
больше 3 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

CVSS3: 6.5
debian
больше 3 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access ...

EPSS

Процентиль: 44%
0.00215
Низкий

Дефекты

CWE-287