Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 15.4  Security Vulnerabilities
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
CVSS Score
6.5
EPSS Score
0.004
Published
2022-10-17
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
CVSS Score
3.5
EPSS Score
0.002
Published
2022-10-17
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.
CVSS Score
2.7
EPSS Score
0.002
Published
2022-10-17
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
CVSS Score
4.3
EPSS Score
0.002
Published
2022-10-17
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-10-17


Contact Us

Shodan ® - All rights reserved