CVE-2022-3902
Published on: Not Yet Published
Last Modified on: 02/01/2023 05:22:00 PM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.
- CVE-2022-3902 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitLab - GitLab version >=9.3, <15.4.6
- Affected Vendor/Software:
GitLab - GitLab version >=15.5, <15.5.5
- Affected Vendor/Software:
GitLab - GitLab version >=15.6, <15.6.1
CVSS3 Score: 6.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
2022/CVE-2022-3902.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
HackerOne | hackerone.com text/html |
![]() |
Webhook secret tokens leaked in webhook logs (#381895) · Issues · GitLab.org / GitLab · GitLab | gitlab.com text/html |
![]() |
Related QID Numbers
- 690999 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (3cde510a-7135-11ed-a28b-bff032704f00)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*:
Discovery Credit
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
Social Mentions
Source | Title | Posted (UTC) |
---|