Логотип exploitDog
bind:CVE-2023-1965
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1965

Количество 3

Количество 3

nvd логотип

CVE-2023-1965

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2023-1965

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cxfp-vwqp-ghxf

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-cxfp-vwqp-ghxf

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу