Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3979

Опубликовано: 29 сент. 2023
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 10.6 (включая) до 16.2.8 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 10.6 (включая) до 16.2.8 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 16.3.0 (включая) до 16.3.5 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 16.3.0 (включая) до 16.3.5 (исключая)
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 19%
0.00059
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVSS3: 3.1
debian
почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
github
почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

EPSS

Процентиль: 19%
0.00059
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo