CVE-2022-1413Insufficiently Protected Credentials in Gitlab

Severity
7.5HIGHNVD
EPSS
0.2%
top 56.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateMay 20

Description

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab1.0.214.8.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=1.0.2, <14.8.6, >=14.10.0, <14.10.1, >=14.9.0, <14.9.4+2
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-chvg-47qc-prxj: Missing input masking in GitLab CE/EE affecting all versions starting from 12022-05-20

📋Vendor Advisories

2
GitLab
CVE-2022-1413: Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versio2022-05-19
Debian
CVE-2022-1413: gitlab - Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2...2022