Логотип exploitDog
bind:CVE-2022-1148
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1148

Количество 4

Количество 4

ubuntu логотип

CVE-2022-1148

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1148

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1148

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5fmm-qcg5-xxr7

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-5fmm-qcg5-xxr7

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 6.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу