CVE-2022-3293

LOW

GitLab EE <15.2.5-15.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

References (2)

Core 2

Scores

CVSS v3 3.5
EPSS 0.0010
EPSS Percentile 26.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
gitlab/gitlab 9.3 - 15.2.5
Published Oct 17, 2022
Tracked Since Feb 18, 2026