CVE-2020-13297 | xxxCVE-2020-13297 – xxx
菜单

CVE-2020-13297

九月 14, 2020 - 未分类

  1. CVE-Search
  2. CVE-2020-13297
ID CVE-2020-13297
SummaryA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.
References
Vulnerable Configurations

    CVSS
    Base: 5.0
    Impact:
    Exploitability:
    Access
    VectorComplexityAuthentication
    Impact
    ConfidentialityIntegrityAvailability
    Last major update14-09-2020 – 22:15
    Published14-09-2020 – 22:15
    Last modified14-09-2020 – 22:15

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51