CVE-2022-2630: Medium severity gitlab vulnerability
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2630?
CVE-2022-2630 is classified as a medium severity vulnerability due to improper access control allowing information disclosure.
How do I fix CVE-2022-2630?
To fix CVE-2022-2630, upgrade to GitLab version 15.2.4 or higher if you are on a version from 15.2, and to 15.3.2 or higher if you are on a version from 15.3.
What versions are affected by CVE-2022-2630?
CVE-2022-2630 affects all GitLab CE/EE versions starting from 15.2 before 15.2.4, and all versions from 15.3 before 15.3.2.
What type of information can be disclosed due to CVE-2022-2630?
CVE-2022-2630 allows the disclosure of confidential information through the Incident timeline events.
Is CVE-2022-2630 present in both GitLab CE and EE editions?
Yes, CVE-2022-2630 affects both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE).