Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-0735

Опубликовано: 28 мар. 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 10

Описание

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

РелизСтатусПримечание
esm-apps/xenial

ignored

not maintainable
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

7.5 High

CVSS2

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
debian
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 9.8
github
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
fstec
больше 3 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками механизма авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

7.5 High

CVSS2

10 Critical

CVSS3