CVE-2022-3902
https://notcve.org/view.php?id=CVE-2022-3902
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.3 anteriores a 15.4.6, todas las versiones desde 15.5 anteriores a 15.5.5, todas las versiones desde 15.6 anteriores a 15.6.1. Un responsable del proyecto pudo desenmascarar los tokens secretos de los webhooks revisando los registros después de probar los webhooks. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3902.json https://gitlab.com/gitlab-org/gitlab/-/issues/381895 https://hackerone.com/reports/1757999 •
CVE-2022-3740
https://notcve.org/view.php?id=CVE-2022-3740
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys . • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3740.json https://gitlab.com/gitlab-org/gitlab/-/issues/368416 https://hackerone.com/reports/1602904 •
CVE-2022-2907
https://notcve.org/view.php?id=CVE-2022-2907
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2907.json https://gitlab.com/gitlab-org/gitlab/-/issues/349388 https://hackerone.com/reports/1417680 •
CVE-2022-3613
https://notcve.org/view.php?id=CVE-2022-3613
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Una consulta del servidor Prometheus manipulada puede provocar un alto consumo de recursos y provocar una denegación de servicio. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3613.json https://gitlab.com/gitlab-org/gitlab/-/issues/378456 https://hackerone.com/reports/1723106 •
CVE-2022-3870
https://notcve.org/view.php?id=CVE-2022-3870
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 10.0 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. GitLab permite a los usuarios no autenticados descargar avatares de usuario utilizando la identificación de usuario de la víctima, en instancias privadas que restringen la visibilidad a nivel público. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3870.json https://gitlab.com/gitlab-org/gitlab/-/issues/381647 https://hackerone.com/reports/1753423 •