Описание
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
Ссылки
- ExploitIssue TrackingVendor Advisory
- Permissions RequiredThird Party Advisory
- ExploitIssue TrackingVendor Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.29 (включая) до 4.0.5 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00096
Низкий
5 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-201
NVD-CWE-Other
Связанные уязвимости
CVSS3: 5
github
больше 2 лет назад
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
EPSS
Процентиль: 27%
0.00096
Низкий
5 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-201
NVD-CWE-Other