CVE-2022-3031
- EPSS 0.55%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 17:15:49
An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute fo...
CVE-2022-3060
- EPSS 0.97%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 17:15:49
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
CVE-2022-3066
- EPSS 0.56%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 17:15:49
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in...
CVE-2022-3067
- EPSS 0.77%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:20
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an aut...
CVE-2022-3279
- EPSS 1.01%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:20
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
CVE-2022-3283
- EPSS 1.42%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content...
CVE-2022-3286
- EPSS 0.47%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token
CVE-2022-3288
- EPSS 0.69%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
CVE-2022-3291
- EPSS 0.77%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
CVE-2022-3293
- EPSS 0.54%
- Veröffentlicht 17.10.2022 16:15:22
- Zuletzt bearbeitet 13.05.2025 16:15:21
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1