Логотип exploitDog
bind:CVE-2021-39881
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-39881

Количество 4

Количество 4

ubuntu логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4ff8-x6j5-88r4

больше 3 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4ff8-x6j5-88r4

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу