CVE-2022-2270

LOW

GitLab 12.4-14.10.4, 15.0-15.0.3, 15.1 - Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/901473

Scores

CVSS v3 3.5
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-276
Status published
Products (2)
gitlab/gitlab 15.1.0 (2 CPE variants)
gitlab/gitlab 12.4.0 - 14.10.5 (2 CPE variants)
Published Jul 01, 2022
Tracked Since Feb 18, 2026