Описание
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
Ссылки
- Vendor Advisory
- Broken Link
- Vendor Advisory
- Broken Link
Уязвимые конфигурации
Одно из
EPSS
5.9 Medium
CVSS3
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
In all versions of GitLab CE/EE since version 8.0, access tokens creat ...
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
EPSS
5.9 Medium
CVSS3
4.9 Medium
CVSS3
4 Medium
CVSS2