Описание
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 12.1.13 (исключая)Версия от 12.2.0 (включая) до 12.2.7 (исключая)Версия от 12.3.0 (включая) до 12.3.3 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 57%
0.00347
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-284
NVD-CWE-Other
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 6 лет назад
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVSS3: 5.3
debian
около 6 лет назад
An improper access control vulnerability exists in Gitlab EE <v12.3.3, ...
CVSS3: 5.3
github
больше 3 лет назад
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
EPSS
Процентиль: 57%
0.00347
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-284
NVD-CWE-Other