Описание
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.
Ссылки
- Release NotesVendor Advisory
- Broken Link
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 18.5.0 (включая) до 18.8.7 (исключая)Версия от 18.9.0 (включая) до 18.9.3 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 5%
0.0002
Низкий
6.8 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 6.8
debian
6 дней назад
GitLab has remediated an issue in GitLab EE affecting all versions fro ...
CVSS3: 6.8
github
6 дней назад
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.
EPSS
Процентиль: 5%
0.0002
Низкий
6.8 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-306