CVE-2022-1545

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-1545
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1545.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1545
Aliases
Published
2022-05-11T15:15:09Z
Modified
2024-11-21T06:40:56Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events