PT-2022-4618 · Gitlab · Gitlab Ce/Ee+1

Yvvdwf

·

Published

2022-08-30

·

Updated

2025-05-13

·

CVE-2022-2630

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.2 through 15.2.3 GitLab CE/EE versions 15.3 through 15.3.1
Description The issue is related to improper access control in GitLab, allowing the disclosure of confidential information via the Incident timeline events. This is due to a lack of protection for internal data, which can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations For GitLab CE/EE versions 15.2 through 15.2.3, update to version 15.2.4 or later. For GitLab CE/EE versions 15.3 through 15.3.1, update to version 15.3.2 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05496
BIT-GITLAB-2022-2630
CVE-2022-2630

Affected Products

Gitlab
Gitlab Ce/Ee