Описание
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
Ссылки
- Vendor Advisory
- Broken Link
- PatchThird Party Advisory
- Vendor Advisory
- Broken Link
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
3.8 Low
CVSS3
4.7 Medium
CVSS3
6 Medium
CVSS2
Дефекты
Связанные уязвимости
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
EPSS
3.8 Low
CVSS3
4.7 Medium
CVSS3
6 Medium
CVSS2