CVE-2022-2761 — Use of a Broken or Risky Cryptographic Algorithm in Gitlab
Severity
5.3MEDIUMNVD
GHSA5.0
EPSS
0.3%
top 48.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 9
Latest updateNov 10
Description
An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages6 packages
🔴Vulnerability Details
3📋Vendor Advisories
2GitLab▶
CVE-2022-2761: An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allow↗2022-11-09
Debian▶
CVE-2022-2761: gitlab - An information disclosure issue in GitLab CE/EE affecting all versions from 14.4...↗2022