MEDIUM

CVE-2022-2270

Gitlab GitLab 2022-07-01 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

Summary dbcve.org

GitLab had an authorization flaw where it incorrectly verified permissions when accessing Conan package information, causing package names to be disclosed to unauthorized users. The vulnerability stems from improper access control logic in the package name resolution endpoint.

Mitigation

Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. After upgrading, verify that unauthorized users can no longer access Conan package names in private projects.

Weakness (CWE)

CWE-276 Incorrect Default Permissions

EPSS Score

0.85%
Probability of exploitation in next 30 days
56.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE