Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45080
HistoryJan 17, 2024 - 7:08 p.m.

Account Take Over

2024-01-1719:08:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
gitlab
vulnerability
account take over
reset emails
administrator password

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7 High

AI Score

Confidence

High

0.96 High

EPSS

Percentile

99.5%

gitlab is vulnerable to Account Take Over. The vulnerability is caused due to a missing validation of email addresses provided while resetting account passwords. An attacker can exploit this vulnerability to send reset emails to an unverified email address and can effectively reset the administrator password.

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7 High

AI Score

Confidence

High

0.96 High

EPSS

Percentile

99.5%