CVE-2022-1413

Source
https://cve.org/CVERecord?id=CVE-2022-1413
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1413.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1413
Aliases
Published
2022-05-19T17:11:12Z
Modified
2026-04-10T04:42:44.987864Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1413.json",
    "cna_assigner": "GitLab"
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.0.2"
        },
        {
            "fixed": "14.8.6"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.9.0"
        },
        {
            "fixed": "14.9.4"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.10.0"
        },
        {
            "fixed": "14.10.1"
        }
    ]
}

Affected versions

v14.*
v14.10.0-ee
v14.9.0-ee
v14.9.1-ee
v14.9.3-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1413.json"