Описание
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
Ссылки
- PatchRelease NotesVendor Advisory
- ExploitVendor Advisory
- Permissions Required
- PatchRelease NotesVendor Advisory
- ExploitVendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 11.5.0 (включая) до 11.11.7 (исключая)Версия от 11.5.0 (включая) до 11.11.7 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 56%
0.0034
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
CWE-639
Связанные уязвимости
CVSS3: 4.3
ubuntu
около 6 лет назад
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
CVSS3: 4.3
debian
около 6 лет назад
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new ...
CVSS3: 4.3
github
больше 3 лет назад
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
EPSS
Процентиль: 56%
0.0034
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
CWE-639