CVE Vulnerabilities

CVE-2022-1413

Insufficiently Protected Credentials

Published: May 19, 2022 | Modified: Aug 08, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 1.0.2 (including) 14.8.6 (excluding)
Gitlab Gitlab 14.9.0 (including) 14.9.4 (excluding)
Gitlab Gitlab 14.10.0 (including) 14.10.0 (including)

Potential Mitigations

References