First published: Mon Mar 28 2022(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.0<14.5.4 | |
GitLab | >=14.6.0<14.6.4 | |
GitLab | =14.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0344 is classified as a medium severity vulnerability.
To fix CVE-2022-0344, upgrade to GitLab version 14.5.4, 14.6.4, or 14.7.1 or later.
The potential impact of CVE-2022-0344 is the unauthorized disclosure of private project paths.
CVE-2022-0344 affects all versions of GitLab starting from 10.0 before 14.5.4, 10.1 before 14.6.4, and 10.2 before 14.7.1.
CVE-2022-0344 occurs when an issue is closed via a merge request, allowing system notes to expose private project paths.