CVE-2022-3293Log File Information Exposure in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 73.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab9.315.2.5+2
CVEListV5gitlab/gitlab>=15.3, <15.3.4, >=15.4, <15.4.1, >=9.3, <15.2.5+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-v92j-h587-3vv3: Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 92022-10-17
OSV
CVE-2022-3293: Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 92022-10-17

📋Vendor Advisories

2
GitLab
CVE-2022-3293: Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.42022-10-17
Debian
CVE-2022-3293: gitlab - Email addresses were leaked in WebHook logs in GitLab EE affecting all versions ...2022