Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3018


An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.


Published

2022-10-28T15:15:15.787

Last Modified

2025-05-07T15:15:54.257

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-532
  • Type: Secondary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.4.1 Yes
Application gitlab gitlab < 15.4.1 Yes

References