Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx3j-3x93-528x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS

Процентиль: 50%
0.00269
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
nvd
больше 4 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
debian
больше 4 лет назад

Certain SAST CiConfiguration information could be viewed by unauthoriz ...

EPSS

Процентиль: 50%
0.00269
Низкий