Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6678

Опубликовано: 12 сент. 2024
Источник: redhat
CVSS3: 9.9
EPSS Низкий

Описание

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

Отчет

Red Hat does not provide GitLab Community Edition (CE) or Enterprise Edition (EE). No Red Hat products are vulnerable to this CVE.

Ссылки на источники

Дополнительная информация

Статус:

Critical
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2312006gitlab: Arbitrary Pipeline Trigger in GitLab

EPSS

Процентиль: 28%
0.001
Низкий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
ubuntu
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

CVSS3: 9.9
nvd
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

CVSS3: 9.9
debian
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.9
github
11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

CVSS3: 9.9
fstec
11 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 28%
0.001
Низкий

9.9 Critical

CVSS3