CVE-2022-2229
HIGHGitLab CE/EE <14.10.5-15.0.4-15.1.1 - Info Disclosure
Title source: llmDescription
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.
Exploits (1)
gitlab
STUB
by hackerone_a0xnirudh · poc
https://gitlab.com/hackerone_a0xnirudh/cve-2022-2229-bypass-demo-deletion_scheduled-79807952
Scores
CVSS v3
7.5
EPSS
0.0022
EPSS Percentile
43.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
Status
published
Affected Products (4)
gitlab/gitlab
< 14.10.5
gitlab/gitlab
< 14.10.5
gitlab/gitlab
gitlab/gitlab
Timeline
Published
Jul 01, 2022
Tracked Since
Feb 18, 2026