Описание
A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-apps/xenial | ignored | not maintainable |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
mantic | DNE | |
noble | DNE | |
upstream | released | 15.10.8+ds1-2 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
A cross-site leak vulnerability in the OAuth flow of all versions of G ...
A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
4.3 Medium
CVSS2
8.8 High
CVSS3