CVE-2022-2270: Medium severity gitlab vulnerability
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2270?
CVE-2022-2270 has a medium severity rating due to its impact on package name leakage.
How do I fix CVE-2022-2270?
To fix CVE-2022-2270, upgrade to GitLab versions 14.10.5, 15.0.4, or 15.1.1 or later.
What versions of GitLab are affected by CVE-2022-2270?
CVE-2022-2270 affects all GitLab versions from 12.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1.
What kind of vulnerability is CVE-2022-2270?
CVE-2022-2270 is a permissions verification vulnerability leading to unauthorized exposure of Conan package names.
Who is affected by CVE-2022-2270?
All users of GitLab community and enterprise editions from the specified affected versions are vulnerable to CVE-2022-2270.