Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2229


An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.


Published

2022-07-01T17:15:07.487

Last Modified

2024-11-21T07:00:35.023

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 14.10.5 Yes
Application gitlab gitlab < 14.10.5 Yes
Application gitlab gitlab < 15.0.4 Yes
Application gitlab gitlab < 15.0.4 Yes
Application gitlab gitlab 15.1.0 Yes
Application gitlab gitlab 15.1.0 Yes

References