Логотип exploitDog
bind:CVE-2024-7404
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7404

Количество 4

Количество 4

nvd логотип

CVE-2024-7404

7 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-7404

7 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-f7c4-9mmj-8w4v

7 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2024-10299

7 месяцев назад

Уязвимость реализации протокола Device OAuth программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю получить несанкционированный доступ к API

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7404

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-7404

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-f7c4-9mmj-8w4v

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2024-10299

Уязвимость реализации протокола Device OAuth программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю получить несанкционированный доступ к API

CVSS3: 6.8
0%
Низкий
7 месяцев назад

Уязвимостей на страницу