Описание
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
An issue was discovered in GitLab CE/EE affecting all versions startin ...
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.
Уязвимость реализации протокола Device OAuth программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю получить несанкционированный доступ к API
EPSS
6.8 Medium
CVSS3
6.5 Medium
CVSS3