CVE-2022-4255
Summary
| CVE | CVE-2022-4255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-27 22:15:00 UTC |
| Updated | 2023-02-06 15:01:00 UTC |
| Description | An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2022/CVE-2022-4255.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| Fix potential security issues in webhook payloads (#373819) · Issues · GitLab.org / GitLab · GitLab | MISC | gitlab.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This vulnerability has been discovered internally by the GitLab team
Legacy QID Mappings
- 379229 GitLab Multiple Security Vulnerabilities (gitlab- 15.6.1, 15.5.5, 15.4.6)