Описание
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.
Ссылки
- Broken Link
- Permissions Required
- Broken Link
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 11.11 (включая) до 16.2.8 (исключая)Версия от 11.11 (включая) до 16.2.8 (исключая)Версия от 16.3.0 (включая) до 16.3.5 (исключая)Версия от 16.3.0 (включая) до 16.3.5 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-286
NVD-CWE-Other
Связанные уязвимости
CVSS3: 5.4
debian
больше 2 лет назад
An issue has been discovered in GitLab EE affecting all versions affec ...
CVSS3: 5.4
github
больше 2 лет назад
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.
EPSS
Процентиль: 11%
0.00038
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-286
NVD-CWE-Other