CVE-2022-3291: Medium severity gitlab vulnerability
Published Oct 17, 2022
·Updated
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
Affected Software
3 affected components
GitLab GitLab>=14.9<15.2.5
GitLab GitLab>=15.3<15.3.4
GitLab GitLab>=15.4<15.4.1
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3291?
CVE-2022-3291 is considered a high severity vulnerability due to potential sensitive data exposure.
2
How do I fix CVE-2022-3291?
To fix CVE-2022-3291, upgrade GitLab EE to version 15.2.5 or later, 15.3.4 or later, or 15.4.1 or later.
3
What versions of GitLab are affected by CVE-2022-3291?
CVE-2022-3291 affects all GitLab EE versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
4
What type of data is exposed due to CVE-2022-3291?
CVE-2022-3291 can leak sensitive information via cache serialization.
5
Is there a workaround for CVE-2022-3291?
Currently, the recommended approach is to upgrade to a fixed version, as no workaround has been documented for CVE-2022-3291.