Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc35-m6pj-p4jm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

EPSS

Процентиль: 28%
0.00095
Низкий

7.5 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
nvd
почти 6 лет назад

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
debian
почти 6 лет назад

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, ...

EPSS

Процентиль: 28%
0.00095
Низкий

7.5 High

CVSS3

Дефекты

CWE-285