An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/384580 | Broken Link |
https://hackerone.com/reports/1780770 | Permissions Required |
https://security.netapp.com/advisory/ntap-20240415-0004/ | |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/384580 | Broken Link |
https://hackerone.com/reports/1780770 | Permissions Required |
https://security.netapp.com/advisory/ntap-20240415-0004/ |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:34
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
References | () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json - Vendor Advisory | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/384580 - Broken Link | |
References | () https://hackerone.com/reports/1780770 - Permissions Required | |
References | () https://security.netapp.com/advisory/ntap-20240415-0004/ - |
14 May 2024, 11:53
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-03-09 21:15
Updated : 2024-11-21 07:34
NVD link : CVE-2022-4289
Mitre link : CVE-2022-4289
CVE.ORG link : CVE-2022-4289
JSON object : View
Products Affected
gitlab
- gitlab
CWE