QID 379229
Date Published: 2024-01-31
QID 379229: GitLab Multiple Security Vulnerabilities (gitlab- 15.6.1, 15.5.5, 15.4.6)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
CVE-2022-3820:GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2
CVE-2022-3740:GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2
CVE-2022-4205:GitLab EE/CE before 15.6.1, 15.5.5 and 15.4.6
CVE-2022-4092:GitLab EE affecting all versions starting from 15.6 before 15.6.1
CVE-2022-3902:GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1
CVE-2022-4054:GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1
CVE-2022-3572:GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2
CVE-2022-3482:GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2
CVE-2022-4255:GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1
CVE-2022-3478:GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1
CVE-2022-4335:GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1
CVE-2022-4201:GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1
Patch Versions:
GitLab Security Release: 15.6.1, 15.5.5 and 15.4.6
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability affects Confidentiality, Integrity, Availability.
- GitLab Security Advisory -
about.gitlab.com/releases/2022/11/30/security-release-gitlab-15-6-1-released/
CVEs related to QID 379229
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|