Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43578
HistoryOct 08, 2023 - 5:05 a.m.

Improper Authorization

2023-10-0805:05:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
improper authorization
gitlab
vulnerability
malicious code
main branch

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.6%

gitlab is vulnerable to Improper Authorization. An attacker can create repositories with malicious code by exploiting a vulnerability in the main branch of a repository with a specially designed name.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.6%