First published: Fri Jul 01 2022(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.4.0<14.10.5 | |
GitLab | >=12.4.0<14.10.5 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | =15.1.0 | |
GitLab | =15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2270 has a medium severity rating due to its impact on package name leakage.
To fix CVE-2022-2270, upgrade to GitLab versions 14.10.5, 15.0.4, or 15.1.1 or later.
CVE-2022-2270 affects all GitLab versions from 12.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1.
CVE-2022-2270 is a permissions verification vulnerability leading to unauthorized exposure of Conan package names.
All users of GitLab community and enterprise editions from the specified affected versions are vulnerable to CVE-2022-2270.