Описание
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
Ссылки
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Patch
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Patch
Уязвимые конфигурации
Конфигурация 1Версия от 6.0.0 (включая) до 6.9.2 (включая)Версия от 7.0.0 (включая) до 7.4.3 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.0032
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 6.5
debian
больше 7 лет назад
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authen ...
CVSS3: 6.5
github
около 3 лет назад
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
EPSS
Процентиль: 54%
0.0032
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-264