GitLab Multiple Vulnerabilities
Release Date:
7 Nov 2022
5580
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution, sensitive information disclosure, cross-site scripting and security restriction bypass on the targeted system.
Impact
- Information Disclosure
- Cross-Site Scripting
- Security Restriction Bypass
- Denial of Service
- Remote Code Execution
- Spoofing
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 15.5.2, 15.4.4, and 15.3.5
- GitLab Enterprise Edition (EE) versions prior to 15.5.2, 15.4.4, and 15.3.5
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2022-2251
- CVE-2022-2761
- CVE-2022-3265
- CVE-2022-3280
- CVE-2022-3413
- CVE-2022-3483
- CVE-2022-3486
- CVE-2022-3706
- CVE-2022-3726
- CVE-2022-3767
- CVE-2022-3793
- CVE-2022-3818
- CVE-2022-3819
Source
Related Link
Related Tags
Share with