Логотип exploitDog
bind:CVE-2023-6944
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6944

Количество 4

Количество 4

redhat логотип

CVE-2023-6944

около 2 лет назад

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-6944

около 2 лет назад

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-86rg-pf4c-5grg

около 2 лет назад

@backstage/backend-app-api leaks GitLab access tokens

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2024-00110

около 2 лет назад

Уязвимость функции catalog-import открытой онлайн-платформа разработки программного обеспечения Red Hat Developer Hub, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-6944

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6944

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-86rg-pf4c-5grg

@backstage/backend-app-api leaks GitLab access tokens

CVSS3: 7.3
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-00110

Уязвимость функции catalog-import открытой онлайн-платформа разработки программного обеспечения Red Hat Developer Hub, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу