CVE-2022-3291

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 07:19

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3291.json - Vendor Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3291.json - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/354299 - Broken Link, Vendor Advisory () https://gitlab.com/gitlab-org/gitlab/-/issues/354299 - Broken Link, Vendor Advisory

Information

Published : 2022-10-17 16:15

Updated : 2024-11-21 07:19


NVD link : CVE-2022-3291

Mitre link : CVE-2022-3291

CVE.ORG link : CVE-2022-3291


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-502

Deserialization of Untrusted Data