2025-01-12 03:03:49 +00:00

64 lines
2.2 KiB
JSON

{
"id": "CVE-2025-0194",
"sourceIdentifier": "cve@gitlab.com",
"published": "2025-01-08T20:15:29.193",
"lastModified": "2025-01-09T07:15:27.667",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en GitLab CE/EE que afectaba a todas las versiones a partir de la 17.4 anterior a la 17.5.5, a partir de la 17.6 anterior a la 17.6.3 y a partir de la 17.7 anterior a la 17.7.1. En determinadas circunstancias, es posible que se hayan registrado tokens de acceso cuando se realizaron solicitudes de API de una manera espec\u00edfica."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cve@gitlab.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.2,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "cve@gitlab.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-538"
}
]
}
],
"references": [
{
"url": "https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#possible-access-token-exposure-in-gitlab-logs",
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/489459",
"source": "cve@gitlab.com"
}
]
}