MEDIUM
CVE-2022-2281
CVSS
5.3
Description
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
Summary dbcve.org
An information disclosure vulnerability in GitLab EE allows unauthorized disclosure of release titles when group milestones are improperly associated with project releases. This is an access control flaw where release metadata is exposed beyond its intended visibility scope.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, or 15.1.1 or later to remediate this information disclosure vulnerability.
EPSS Score
0.91%
Probability of exploitation in next 30 days
58.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.