Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-15387

Опубликовано: 26 авг. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 19.1.0 (включая) до 19.1.7 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 19.2.0 (включая) до 19.2.5 (исключая)
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 11%
0.00204
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-349

Связанные уязвимости

CVSS3: 4.3
github
29 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.

EPSS

Процентиль: 11%
0.00204
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-349