CVE-2023-1178

MEDIUM5.7EPSS 9.2%
發布日:2024/3/6修改日:2025/4/3

描述

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

受影響套件(1)

  • Bitnami/gitlab>= 8.6.0, < 15.9.6, >= 15.10.0, < 15.10.5, >= 15.11.0, < 15.11.1

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

參考連結(4)