An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2229.json | Vendor Advisory |
https://hackerone.com/reports/1511133 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/355738 | Broken Link |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-01 10:15
Updated : 2022-07-13 11:44
NVD link : CVE-2022-2229
Mitre link : CVE-2022-2229
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
gitlab
- gitlab