Описание
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
Ссылки
- ExploitIssue TrackingVendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 16.8.0 (включая) до 18.5.0 (исключая)Версия от 16.8.0 (включая) до 18.5.0 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 3%
0.00014
Низкий
3.1 Low
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 3.1
ubuntu
около 2 месяцев назад
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
CVSS3: 3.1
debian
около 2 месяцев назад
A vulnerability has been discovered in GitLab CE/EE affecting all vers ...
CVSS3: 3.1
github
около 2 месяцев назад
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
EPSS
Процентиль: 3%
0.00014
Низкий
3.1 Low
CVSS3
Дефекты
CWE-862