CVE-2022-3067

MEDIUM

GitLab CE/EE <15.2.5-15.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

References (3)

Core 3

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
gitlab/gitlab 14.4 - 15.2.5 (2 CPE variants)
Published Oct 17, 2022
Tracked Since Feb 18, 2026