Vulnerabilities > Gitlab > Gitlab > 15.0.4

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-3288 Unspecified vulnerability in Gitlab
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3291 Deserialization of Untrusted Data vulnerability in Gitlab
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
network
low complexity
gitlab CWE-502
6.5
2022-10-17 CVE-2022-3293 Information Exposure Through Log Files vulnerability in Gitlab
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
network
low complexity
gitlab CWE-532
4.3
2022-10-17 CVE-2022-3325 Unspecified vulnerability in Gitlab
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3330 Unspecified vulnerability in Gitlab
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3331 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
low complexity
gitlab CWE-639
4.3
2022-10-17 CVE-2022-3351 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab
4.3
2022-08-05 CVE-2022-2303 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-287
4.3
2022-08-05 CVE-2022-2456 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
2.7
2022-08-05 CVE-2022-2459 Missing Authorization vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-862
2.7