CVE-2022-1413 — Insufficiently Protected Credentials in Gitlab
Severity
7.5HIGHNVD
EPSS
0.2%
top 56.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 19
Latest updateMay 20
Description
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-chvg-47qc-prxj: Missing input masking in GitLab CE/EE affecting all versions starting from 1↗2022-05-20
📋Vendor Advisories
2GitLab▶
CVE-2022-1413: Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versio↗2022-05-19
Debian▶
CVE-2022-1413: gitlab - Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2...↗2022