CVE-2022-0390
Published Apr 1, 2022
Last updated a year ago
Overview
- Description
- Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:N/AC:H/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-862
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "A3E62CCA-B6FF-4834-9264-CED86BF0FEB1", "versionEndIncluding": "14.5.4", "versionStartIncluding": "12.7.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "A4A5D04B-E18D-461F-95C4-A5409E730EAC", "versionEndIncluding": "14.5.4", "versionStartIncluding": "12.7.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "6614BCF7-A0FF-47DD-8FEC-EE85002B95FA", "versionEndIncluding": "14.6.4", "versionStartIncluding": "14.6.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "BC7C0DFD-980D-4B75-8EA1-6E92D07691FF", "versionEndIncluding": "14.6.4", "versionStartIncluding": "14.6.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "E1777EA5-F6AF-4ED5-8FC9-831E07928413" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "54B6C3BE-A861-456C-9319-A61E2041BE32" } ], "operator": "OR" } ] } ]