CVE-2022-3291Deserialization of Untrusted Data in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 36.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab14.915.2.5+2
CVEListV5gitlab/gitlab>=14.9, <15.2.5, >=15.3, <15.3.4, >=15.4, <15.4.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2022-3291: Serialization of sensitive data in GitLab EE affecting all versions from 142022-10-17
GHSA
GHSA-hgr5-p9jr-23mm: Serialization of sensitive data in GitLab EE affecting all versions from 142022-10-17

📋Vendor Advisories

2
GitLab
CVE-2022-3291: Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak2022-10-17
Debian
CVE-2022-3291: gitlab - Serialization of sensitive data in GitLab EE affecting all versions from 14.9 pr...2022