Lucene search

K
githubGitHub Advisory DatabaseGHSA-CG6R-GQVC-R396
HistoryJul 26, 2023 - 3:30 p.m.

CSRF vulnerability in GitLab Authentication Plugin

2023-07-2615:30:57
CWE-352
GitHub Advisory Database
github.com
11
gitlab
authentication
csrf
vulnerability
oauth

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

29.0%

GitLab Authentication Plugin 1.17.1 and earlier does not implement a state parameter in its OAuth flow, a unique and non-guessable value associated with each authentication request.

This vulnerability allows attackers to trick users into logging in to the attacker’s account.

GitLab Authentication Plugin 1.18 implements a state parameter in its OAuth flow.

Affected configurations

Vulners
Node
wp-oauthwp_oauth_serverRange<1.18wordpress

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

29.0%

Related for GHSA-CG6R-GQVC-R396