CVE-2020-2228
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
8.1
HIGH
CVSS 3.1
EPSS 1.4%
描述
GitLab Authentication Plugin 1.5 and earlier does not differentiate between user names and hierarchical group names when performing authorization. This allows an attacker with permissions to create groups in GitLab to gain the privileges granted to another user or group. GitLab Authentication Plugin 1.6 performs user name and group name authorization checks using the appropriate GitLab APIs.
如何修補 CVE-2020-2228
要修補 CVE-2020-2228,請將受影響套件升級到下列已修補版本。
- —升級至 1.6 或更新版本
CVE-2020-2228 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |