MEDIUM

CVE-2022-1963

Gitlab GitLab 2022-07-01 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

Summary dbcve.org

GitLab CE/EE exposes whether a user has enabled two-factor authentication in the HTML source to unauthenticated (non-logged-in) visitors. This information disclosure occurs through the user interface or API responses that include 2FA status in page HTML, allowing attackers to enumerate which accounts have enhanced security.

Mitigation

Upgrade GitLab to versions 14.10.5, 15.0.4, 15.1.1 or later. Self-hosted deployments should apply the patch version corresponding to their current major release.

EPSS Score

1.37%
Probability of exploitation in next 30 days
70.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE