CVE-2022-3279: Medium severity gitlab vulnerability
Published Oct 17, 2022
·Updated
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
Affected Software
6 affected components
GitLab GitLab<15.2.5
GitLab GitLab<15.2.5
GitLab GitLab>=15.3<15.3.4
GitLab GitLab>=15.3<15.3.4
GitLab GitLab>=15.4<15.4.1
GitLab GitLab>=15.4<15.4.1
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3279?
CVE-2022-3279 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-3279?
To fix CVE-2022-3279, you should upgrade GitLab to version 15.2.5 or later, or to version 15.3.4 or later, or to version 15.4.1 or later.
3
What effect does CVE-2022-3279 have on GitLab installations?
CVE-2022-3279 allows an attacker to prevent access to job logs in affected versions of GitLab.
4
Which versions of GitLab are affected by CVE-2022-3279?
CVE-2022-3279 affects all versions of GitLab prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
5
Are both GitLab CE and EE impacted by CVE-2022-3279?
Yes, both GitLab Community Edition (CE) and Enterprise Edition (EE) are impacted by CVE-2022-3279.