Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x995-4q6w-crwj

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

EPSS

Процентиль: 37%
0.00151
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 2 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
nvd
больше 2 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
debian
больше 2 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...

CVSS3: 7.3
fstec
почти 3 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостаточной проверкой входных данных, позволяющая нарушителю внедрить произвольные данные

EPSS

Процентиль: 37%
0.00151
Низкий

8 High

CVSS3

Дефекты

CWE-79