First published: Fri Jul 01 2022(Updated: )
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.5.0<14.10.5 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | =15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2281 is classified as an information disclosure vulnerability.
To fix CVE-2022-2281, upgrade GitLab EE to version 14.10.5, 15.0.4, or 15.1.1 or later.
CVE-2022-2281 affects all GitLab EE versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1.
CVE-2022-2281 is an information disclosure vulnerability specifically related to the disclosure of release titles.
CVE-2022-2281 allows unauthorized users to potentially access and disclose information about project release titles.