Описание
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
Ссылки
- Third Party Advisory
- Broken Link
- Permissions Required
- Third Party Advisory
- Broken Link
- Permissions Required
Уязвимые конфигурации
Одно из
EPSS
5.4 Medium
CVSS3
4.5 Medium
CVSS3
Дефекты
Связанные уязвимости
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
An issue has been discovered in GitLab affecting all versions starting ...
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
EPSS
5.4 Medium
CVSS3
4.5 Medium
CVSS3