Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3291


Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache


Published

2022-10-17T16:15:22.567

Last Modified

2025-05-13T16:15:21.780

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-502
  • Type: Secondary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.4.1 Yes

References