CVE-2020-13302 | xxxCVE-2020-13302 – xxx
菜单

CVE-2020-13302

九月 14, 2020 - 未分类

  1. CVE-Search
  2. CVE-2020-13302
ID CVE-2020-13302
SummaryA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
References
Vulnerable Configurations

    CVSS
    Base: 5.0
    Impact:
    Exploitability:
    Access
    VectorComplexityAuthentication
    Impact
    ConfidentialityIntegrityAvailability
    Last major update14-09-2020 – 22:15
    Published14-09-2020 – 22:15
    Last modified14-09-2020 – 22:15

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51