CVE-2022-0390
01.04.2022, 23:15
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 12.7.0 ≤ 𝑥 ≤ 14.5.4 |
gitlab | gitlab | 12.7.0 ≤ 𝑥 ≤ 14.5.4 |
gitlab | gitlab | 14.6.0 ≤ 𝑥 ≤ 14.6.4 |
gitlab | gitlab | 14.6.0 ≤ 𝑥 ≤ 14.6.4 |
gitlab | gitlab | 14.7.0 |
gitlab | gitlab | 14.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References