Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41344
HistoryJul 18, 2023 - 5:23 p.m.

Resource Injection

2023-07-1817:23:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
gitlab vulnerability
resource injection
arbitrary code
protected branches

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.4%

gitlab is vulnerable to Resource Injection. The vulnerability allows an attacker to merge arbitrary code into protected branches.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.4%