First published: Thu May 19 2022(Updated: )
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=1.0.2<14.8.6 | |
GitLab | >=1.0.2<14.8.6 | |
GitLab | >=14.9.0<14.9.4 | |
GitLab | >=14.9.0<14.9.4 | |
GitLab | =14.10.0 | |
GitLab | =14.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1413 is rated as a medium severity vulnerability due to its potential to disclose sensitive information.
To fix CVE-2022-1413, upgrade to GitLab CE/EE version 14.8.6, 14.9.4, or 14.10.1 or later.
CVE-2022-1413 affects GitLab CE/EE versions starting from 1.0.2 to 14.8.6, from 14.9.0 to before 14.9.4, and 14.10.0 to before 14.10.1.
CVE-2022-1413 can potentially expose sensitive integration properties in the web interface.
Yes, CVE-2022-1413 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.