Логотип exploitDog
bind:CVE-2024-1525
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-1525

Количество 5

Количество 5

ubuntu логотип

CVE-2024-1525

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-1525

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-1525

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v36-29xm-jp89

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-01677

около 2 лет назад

Уязвимость реализации LDAP-аутентификации программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю сбросить пароль произвольного пользователя и осуществить вход в систему

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2v36-29xm-jp89

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-01677

Уязвимость реализации LDAP-аутентификации программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю сбросить пароль произвольного пользователя и осуществить вход в систему

CVSS3: 5.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу