QID 379233
Date Published: 2024-01-15
QID 379233: GitLab EE Insecure Direct Object References (IDOR) Vulnerability (CVE-2022-3331)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2022-3331: An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.
Affected Versions:
GitLab EE versions starting from 14.5 upto 15.1.5
GitLab EE versions starting from 15.2 upto 15.2.3
GitLab EE versions starting from 15.3 upto 15.3.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability may lead to insecure direct object reference that may result into leakage of Zentao Project issues
- GitLab Security Advisory -
about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/
CVEs related to QID 379233
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Releases |
|