An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51696 | An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile. |
Fixes
Solution
Upgrade to versions 16.1.5, 16.2.5, 16.3.1 or above.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-22T04:04:33.478Z
Reserved: 2022-12-07T23:10:52.570Z
Link: CVE-2022-4343
Updated: 2024-08-03T01:34:50.162Z
Status : Modified
Published: 2023-09-01T11:15:40.037
Modified: 2024-11-21T07:35:05.593
Link: CVE-2022-4343
No data.
OpenCVE Enrichment
No data.
EUVD