Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh8q-q4r3-6x29

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

EPSS

Процентиль: 21%
0.00068
Низкий

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 3 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

CVSS3: 4.4
nvd
больше 3 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

CVSS3: 4.4
debian
больше 3 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, a ...

EPSS

Процентиль: 21%
0.00068
Низкий

Дефекты

CWE-640