CVE Vulnerabilities

CVE-2022-3793

Published: Nov 10, 2022 | Modified: Nov 10, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they dont have access to.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.6.0 (including) 15.3.5 (excluding)
Gitlab Gitlab 15.4.0 (including) 15.4.4 (excluding)
Gitlab Gitlab 15.5.0 (including) 15.5.2 (excluding)

References