Описание
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions.
Ссылки
- Release NotesVendor Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия от 13.11.0 (включая) до 18.11.6 (исключая)Версия от 19.0.0 (включая) до 19.0.3 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 9%
0.00188
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 5.3
github
около 1 месяца назад
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions.
EPSS
Процентиль: 9%
0.00188
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863