CVE-2022-2761Use of a Broken or Risky Cryptographic Algorithm in Gitlab

Severity
5.3MEDIUMNVD
GHSA5.0
EPSS
0.3%
top 48.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateNov 10

Description

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

NVDgitlab/gitlab13.9.015.3.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=13.9, <15.3.5, >=15.4, <15.4.4, >=15.5, <15.5.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

3
GHSA
GHSA-c3wj-324v-hrrc: An information disclosure issue in GitLab CE/EE affecting all versions from 142022-11-10
OSV
CVE-2022-2761: An information disclosure issue in GitLab CE/EE affecting all versions from 142022-11-09
GHSA
SIF's Digital Signature Hash Algorithms Not Validated2022-10-06

📋Vendor Advisories

2
GitLab
CVE-2022-2761: An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allow2022-11-09
Debian
CVE-2022-2761: gitlab - An information disclosure issue in GitLab CE/EE affecting all versions from 14.4...2022