CVE-2022-3067
- EPSS 0.24%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:20
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an aut...
CVE-2022-3279
- EPSS 0.71%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:20
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
CVE-2022-3283
- EPSS 0.54%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content...
CVE-2022-3286
- EPSS 0.12%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token
CVE-2022-3288
- EPSS 0.16%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
CVE-2022-3291
- EPSS 0.45%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
CVE-2022-3293
- EPSS 0.1%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
CVE-2022-3325
- EPSS 0.19%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:22
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API ...
CVE-2022-3330
- EPSS 0.16%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 21.11.2024 07:19:18
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
CVE-2022-3331
- EPSS 0.17%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 14.05.2025 21:15:54
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object...