An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-51725 An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-02-12T16:05:51.793Z

Reserved: 2022-12-09T00:00:00.000Z

Link: CVE-2022-4376

cve-icon Vulnrichment

Updated: 2024-08-03T01:41:44.382Z

cve-icon NVD

Status : Modified

Published: 2023-05-03T22:15:15.793

Modified: 2024-11-21T07:35:09.627

Link: CVE-2022-4376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.