Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42592
HistoryAug 07, 2023 - 2:24 a.m.

Race Condition

2023-08-0702:24:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
gitlab
vulnerability
account takeover
race condition
exploit
third-party
data theft

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.7%

gitlab is vulnerable to Race Condition. An attacker could exploit this vulnerability by tricking a GitLab user into visiting a malicious website. Once the user visits the malicious website, the attacker could exploit the vulnerability to forge a verified email and take over their third-party account. This could allow the attacker to steal data, modify settings, or perform other actions on the third-party account.

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.7%