MEDIUM
CVE-2022-3291
CVSS
6.5
Description
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
Summary dbcve.org
In affected GitLab EE versions, sensitive data is being serialized and stored in cache in a manner that allows unauthorized access to that sensitive information. This represents a data exposure vulnerability where cached serialized data can be leaked.
Mitigation
Upgrade GitLab EE to version 15.2.5, 15.3.4, or 15.4.1 (or later) to patch this vulnerability. Consider clearing any existing cache to remove potentially exposed sensitive data.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
0.78%
Probability of exploitation in next 30 days
54.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.