Severity
6.1MEDIUMNVD
CISA8.8CISA7.8
EPSS
0.2%
top 57.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 1
Latest updateJul 2

Description

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDgitlab/gitlab14.0.014.4.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=14.0, <14.4.5, >=14.5.0, <14.5.3, >=14.6.0, <14.6.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-gfj2-5hv5-w3x2: An issue has been discovered in GitLab affecting all versions starting from 142022-07-02

📋Vendor Advisories

4
GitLab
CVE-2022-0167: An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all v2022-07-01
CISA
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability2022-03-03
Debian
CVE-2022-0167: gitlab - An issue has been discovered in GitLab affecting all versions starting from 14.0...2022
CISA
Microsoft Win32k Privilege Escalation Vulnerability2021-11-03