Логотип exploitDog
bind:CVE-2023-6680
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6680

Количество 5

Количество 5

ubuntu логотип

CVE-2023-6680

почти 2 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2023-6680

почти 2 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2023-6680

почти 2 года назад

An improper certificate validation issue in Smartcard authentication i ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-wpj8-2grx-f965

почти 2 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2024-00232

почти 2 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с некорректной проверкой сертификата при аутентификации по смарт-картам, позволяющая нарушителю пройти проверку подлинности как другой пользователь

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication i ...

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-wpj8-2grx-f965

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-00232

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с некорректной проверкой сертификата при аутентификации по смарт-картам, позволяющая нарушителю пройти проверку подлинности как другой пользователь

CVSS3: 8.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу