CVE-2022-3482 Information

Description

An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5 15.4 prior to 15.4.4 and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only

Reference

https://gitlab.com/gitlab-org/gitlab/-/issues/377802 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.json https://hackerone.com/reports/1725841

Share on: