MEDIUM

CVE-2022-4255

Gitlab GitLab 2023-01-27 CVSS v3.1
CVSS
5.3

Description

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

Summary dbcve.org

This is an information disclosure vulnerability in GitLab EE where user email addresses are inadvertently exposed in webhook payloads. The issue affects multiple versions (13.7 through 15.6) and allows sensitive PII to potentially leak to external systems via configured webhooks.

Mitigation

Upgrade GitLab EE to version 15.4.6, 15.5.5, or 15.6.1 (or later) to patch the vulnerability. Review existing webhook configurations for any unintended exposure of user email data.

EPSS Score

0.49%
Probability of exploitation in next 30 days
41.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE