4.3

CVE-2022-3293

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition enterprise Version >= 9.3 < 15.2.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 15.3 < 15.3.4
Gitlab ≫ GitLab SwEdition enterprise Version >= 15.4 < 15.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.426
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cve@gitlab.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3293.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/369008
Vendor Advisory
Broken Link