Описание
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
Ссылки
- ExploitIssue TrackingVendor Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingVendor Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:gitlab:gitlab:12.0.4:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:12.1.2:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 41%
0.00193
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-288
CWE-287
Связанные уязвимости
CVSS3: 7.2
ubuntu
больше 6 лет назад
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
CVSS3: 7.2
debian
больше 6 лет назад
An authentication issue was discovered in GitLab that allowed a bypass ...
CVSS3: 7.2
github
больше 3 лет назад
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
EPSS
Процентиль: 41%
0.00193
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-288
CWE-287