MEDIUM
CVE-2022-2270
CVSS
5.3
Description
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.
Summary dbcve.org
GitLab had an authorization flaw where it incorrectly verified permissions when accessing Conan package information, causing package names to be disclosed to unauthorized users. The vulnerability stems from improper access control logic in the package name resolution endpoint.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. After upgrading, verify that unauthorized users can no longer access Conan package names in private projects.
Weakness (CWE)
CWE-276
Incorrect Default Permissions
EPSS Score
0.85%
Probability of exploitation in next 30 days
56.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.