CVE-2022-4255Gitlab vulnerability

4 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 66.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateJan 28

Description

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.7.015.4.6+2
CVEListV5gitlab/gitlab>=13.7, <15.4.6, >=15.5, <15.5.5, >=15.6, <15.6.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-87v5-hm46-mgp6: An info leak issue was identified in all versions of GitLab EE from 132023-01-28

📋Vendor Advisories

2
GitLab
CVE-2022-4255: An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes2023-01-27
Debian
CVE-2022-4255: gitlab - An info leak issue was identified in all versions of GitLab EE from 13.7 prior t...2022