[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Information exposure vulnerability in GitLab EE - CVE-2022-2228 (rpm)

ID: oval:org.secpod.oval:def:84684Date: (C)2022-10-04   (M)2023-08-03
Class: VULNERABILITYFamily: unix




The host is installed with GitLab EE 12.0 before 14.10.5, 15.0 before 15.0.4 or 15.1 before 15.1.1 and is prone to an information exposure vulnerability. A flaw is present in the application, which fails to properly handle issues in unspecified vectors. Successful exploitation could allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range.

Platform:
Linux
Product:
gitlab-ee
Reference:
CVE-2022-2228
CVE    1
CVE-2022-2228

© SecPod Technologies