6.4

CVE-2022-3902

Exploit
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 9.3.0 < 15.4.6
Gitlab ≫ GitLab SwEdition enterprise Version >= 9.3.0 < 15.4.6
Gitlab ≫ GitLab SwEdition community Version >= 15.5.0 < 15.5.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 15.5.0 < 15.5.5
Gitlab ≫ GitLab Version 15.6.0 SwEdition community
Gitlab ≫ GitLab Version 15.6.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 3.1 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
cve@gitlab.com 5.5 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3902.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/381895
Vendor Advisory
Exploit
Issue Tracking
https://hackerone.com/reports/1757999
Third Party Advisory
Permissions Required