Описание
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
Ссылки
- Vendor Advisory
- Broken Link
- Permissions RequiredThird Party Advisory
- Vendor Advisory
- Broken Link
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.5.0 (включая) до 14.5.4 (включая)Версия от 14.6 (включая) до 14.6.4 (включая)Версия от 14.7.0 (включая) до 14.7.1 (включая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00198
Низкий
5.4 Medium
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5.4
ubuntu
почти 4 года назад
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
CVSS3: 5.4
debian
почти 4 года назад
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 ...
CVSS3: 8.1
github
почти 4 года назад
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
EPSS
Процентиль: 42%
0.00198
Низкий
5.4 Medium
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-918