Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
GitLab heeft kwetsbaarheden verholpen in GitLab Community Edition (CE) en Enterprise Edition (EE).
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of om beveiligingsmaatregelen te omzeilen en zo toegang te krijgen tot projecten waar de kwaadwillende aanvankelijk niet voor is geautoriseerd.
- Oplossingen
GitLab heeft updates uitgebracht om de kwetsbaarheden te verhelpen in GitLab EE en CE v 17.2.2, 17.1.4 & 17.0.6. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-116
Improper Encoding or Escaping of Output
- CWE-305
Authentication Bypass by Primary Weakness
- CWE-400
Uncontrolled Resource Consumption
- CWE-639
Authorization Bypass Through User-Controlled Key
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-94
Improper Control of Generation of Code ('Code Injection')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard