Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-0740

Опубликовано: 04 апр. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 3.1

Описание

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

РелизСтатусПримечание
esm-apps/xenial

ignored

not maintainable
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 30%
0.00105
Низкий

4 Medium

CVSS2

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 3.1
debian
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction ...

CVSS3: 4.3
github
около 3 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

EPSS

Процентиль: 30%
0.00105
Низкий

4 Medium

CVSS2

3.1 Low

CVSS3