CVE-2022-2907

MEDIUM

GitLab 12.9-15.1.5, 15.2-15.2.3, 15.3-15.3.1 - Unauthenticated Repository Content Exposure via Crafted Link

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

References (3)

Core 3

Scores

CVSS v3 5.7
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
gitlab/gitlab 12.9 - 15.1.6 (2 CPE variants)
Published Jan 17, 2023
Tracked Since Feb 18, 2026