First published: Mon Oct 17 2022(Updated: )
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.2<15.2.4 | |
GitLab | >=15.2<15.2.4 | |
GitLab | >=15.3<15.3.2 | |
GitLab | >=15.3<15.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2630 is classified as a medium severity vulnerability due to improper access control allowing information disclosure.
To fix CVE-2022-2630, upgrade to GitLab version 15.2.4 or higher if you are on a version from 15.2, and to 15.3.2 or higher if you are on a version from 15.3.
CVE-2022-2630 affects all GitLab CE/EE versions starting from 15.2 before 15.2.4, and all versions from 15.3 before 15.3.2.
CVE-2022-2630 allows the disclosure of confidential information through the Incident timeline events.
Yes, CVE-2022-2630 affects both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE).