Описание
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
Ссылки
- Vendor Advisory
- Broken Link
- Permissions Required
- Vendor Advisory
- Broken Link
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 13.6.0 (включая) до 14.1.7 (исключая)Версия от 13.6.0 (включая) до 14.1.7 (исключая)Версия от 14.2.0 (включая) до 14.2.5 (исключая)Версия от 14.2.0 (включая) до 14.2.5 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 57%
0.00951
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 5.4
ubuntu
почти 5 лет назад
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVSS3: 5.4
debian
почти 5 лет назад
A business logic error in the project deletion process in GitLab 13.6 ...
CVSS3: 5.4
github
около 4 лет назад
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
EPSS
Процентиль: 57%
0.00951
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo