Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0989

Опубликовано: 29 сент. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 5.7
EPSS Низкий

Описание

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 13.11 (включая) до 16.2.8 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 13.11 (включая) до 16.2.8 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 16.3.0 (включая) до 16.3.5 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 16.3.0 (включая) до 16.3.5 (исключая)
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 20%
0.00065
Низкий

4.3 Medium

CVSS3

5.7 Medium

CVSS3

Дефекты

CWE-282
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
debian
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
github
больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

EPSS

Процентиль: 20%
0.00065
Низкий

4.3 Medium

CVSS3

5.7 Medium

CVSS3

Дефекты

CWE-282
NVD-CWE-noinfo