Логотип exploitDog
bind:CVE-2023-3932
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3932

Количество 5

Количество 5

redhat логотип

CVE-2023-3932

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

EPSS: Низкий
nvd логотип

CVE-2023-3932

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-3932

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-vvcp-5v5p-8jhc

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2023-07398

почти 2 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связнная с недостатками процедуры авторизации, позволяющая нарушителю запускать задания конвейера от имени произвольного пользователя

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 8.2
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-vvcp-5v5p-8jhc

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-07398

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связнная с недостатками процедуры авторизации, позволяющая нарушителю запускать задания конвейера от имени произвольного пользователя

CVSS3: 8.2
0%
Низкий
почти 2 года назад

Уязвимостей на страницу