CVE-2022-4255 — Gitlab vulnerability
4 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 66.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 27
Latest updateJan 28
Description
An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-87v5-hm46-mgp6: An info leak issue was identified in all versions of GitLab EE from 13↗2023-01-28
📋Vendor Advisories
2GitLab▶
CVE-2022-4255: An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes↗2023-01-27
Debian▶
CVE-2022-4255: gitlab - An info leak issue was identified in all versions of GitLab EE from 13.7 prior t...↗2022