[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Incorrect authorization vulnerability in GitLab CE/EE - CVE-2022-2229 (dpkg)

ID: oval:org.secpod.oval:def:84665Date: (C)2022-10-04   (M)2023-08-16
Class: VULNERABILITYFamily: unix




The host is installed with GitLab CE/EE 13.7 before 14.10.5, 15.0 before 15.0.4 or 15.1 before 15.1.1 and is prone to an incorrect authorization vulnerability. A flaw is present in the application, which fails to properly handle issues in unspecified vectors. Successful exploitation could allows attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

Platform:
Linux
Product:
gitlab-ce
gitlab-ee
Reference:
CVE-2022-2229
CVE    1
CVE-2022-2229

© SecPod Technologies