Описание
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
Ссылки
- ExploitIssue TrackingVendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 16.8.0 (включая) до 18.5.0 (исключая)Версия от 16.8.0 (включая) до 18.5.0 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 1%
0.00012
Низкий
3.1 Low
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 3.1
ubuntu
6 дней назад
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
CVSS3: 3.1
debian
6 дней назад
A vulnerability has been discovered in GitLab CE/EE affecting all vers ...
CVSS3: 3.1
github
6 дней назад
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
EPSS
Процентиль: 1%
0.00012
Низкий
3.1 Low
CVSS3
Дефекты
CWE-862