CVE-2022-0738

MEDIUM

GitLab <14.6.5-14.8.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

References (2)

Core 2
Core References

Scores

CVSS v3 4.2
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (1)
gitlab/gitlab 10.0 - 14.6.5 (2 CPE variants)
Published Mar 28, 2022
Tracked Since Feb 18, 2026