Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-0427

Опубликовано: 28 мар. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.7

Описание

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

РелизСтатусПримечание
esm-apps/xenial

ignored

not maintainable
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 31%
0.00119
Низкий

6.8 Medium

CVSS2

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
debian
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

CVSS3: 8.8
github
почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

EPSS

Процентиль: 31%
0.00119
Низкий

6.8 Medium

CVSS2

7.7 High

CVSS3