CVE-2022-2761
Published on: Not Yet Published
Last Modified on: 11/11/2022 12:53:00 AM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.
- CVE-2022-2761 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitLab - GitLab version >=13.9, <15.3.5
- Affected Vendor/Software:
GitLab - GitLab version >=15.4, <15.4.4
- Affected Vendor/Software:
GitLab - GitLab version >=15.5, <15.5.2
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Not Found | gitlab.com text/html Inactive LinkNot Archived |
![]() |
HackerOne | hackerone.com text/html |
![]() |
2022/CVE-2022-2761.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
Related QID Numbers
- 690975 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (16f7ec68-5cce-11ed-9be7-454b1dd82c64)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | All | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
Discovery Credit
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-2761 : An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 1… twitter.com/i/web/status/1… | 2022-11-09 23:05:38 |
![]() |
CVE-2022-2761 | 2022-11-10 00:38:31 |