MEDIUM

CVE-2022-3291

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
6.5

Description

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

Summary dbcve.org

In affected GitLab EE versions, sensitive data is being serialized and stored in cache in a manner that allows unauthorized access to that sensitive information. This represents a data exposure vulnerability where cached serialized data can be leaked.

Mitigation

Upgrade GitLab EE to version 15.2.5, 15.3.4, or 15.4.1 (or later) to patch this vulnerability. Consider clearing any existing cache to remove potentially exposed sensitive data.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

0.78%
Probability of exploitation in next 30 days
54.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE