Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-4658

Опубликовано: 01 дек. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 3.1

Описание

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the Allowed to merge permission as a guest user, when granted the permission through a group.

РелизСтатусПримечание
bionic

not-affected

gitlab EE only
devel

DNE

esm-apps/xenial

not-affected

gitlab EE only
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

trusty

not-affected

gitlab EE only
upstream

not-affected

debian: Specific to EE

Показывать по

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
debian
около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
github
около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

3.1 Low

CVSS3