PT-2022-13869 · Gitlab · Gitlab Ce/Ee+1

Published

2022-05-19

·

Updated

2024-03-06

·

CVE-2022-1413

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 1.0.2 through 14.8.6 GitLab CE/EE versions 14.9.0 through 14.9.4 GitLab CE/EE versions 14.10.0 through 14.10.1
Description The issue is related to missing input masking in GitLab CE/EE, which causes potentially sensitive integration properties to be disclosed in the web interface.
Recommendations For versions 1.0.2 through 14.8.6, update to version 14.8.6 or later. For versions 14.9.0 through 14.9.4, update to version 14.9.4 or later. For versions 14.10.0 through 14.10.1, update to version 14.10.1 or later.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1413
CVE-2022-1413

Affected Products

Gitlab
Gitlab Ce/Ee