Описание
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
Ссылки
- Third Party Advisory
- Broken LinkThird Party Advisory
- Permissions RequiredThird Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.9 Critical
CVSS3
Дефекты
Связанные уязвимости
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
Уязвимость функции импорта из GitHub программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю выполнить произвольный код
EPSS
9.9 Critical
CVSS3