Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4054


An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.


Published

2023-01-26T21:18:06.253

Last Modified

2025-04-02T16:15:23.717

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.4.6 Yes
Application gitlab gitlab < 15.4.6 Yes
Application gitlab gitlab < 15.5.5 Yes
Application gitlab gitlab < 15.5.5 Yes
Application gitlab gitlab 15.6.0 Yes
Application gitlab gitlab 15.6.0 Yes

References