CVE-2022-3820
https://notcve.org/view.php?id=CVE-2022-3820
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location. Se descubrió un problema en GitLab que afecta a todas las versiones desde la 15.4 anterior a la 15.4.4 y la 15.5 anterior a la 15.5.2. GitLab no estaba realizando la autenticación correcta con algunos registros de paquetes cuando se configuraron las restricciones de dirección IP, lo que permitió que un atacante que ya estuviera en posesión de un token de implementación válido lo usara indebidamente desde cualquier ubicación. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json https://gitlab.com/gitlab-org/gitlab/-/issues/378638 •
CVE-2022-3572
https://notcve.org/view.php?id=CVE-2022-3572
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims. Se descubrió un problema de cross site scripting en GitLab CE/EE que afecta a todas las versiones desde 13.5 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2. Fue posible explotar una vulnerabilidad al configurar la integración de Jira Connect, lo que podría conducir a un XSS reflejado que permitiera a los atacantes realizar acciones arbitrarias en nombre de las víctimas. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3572.json https://gitlab.com/gitlab-org/gitlab/-/issues/378214 https://hackerone.com/reports/1727985 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-3482
https://notcve.org/view.php?id=CVE-2022-3482
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.json https://gitlab.com/gitlab-org/gitlab/-/issues/377802 https://hackerone.com/reports/1725841 • CWE-862: Missing Authorization •
CVE-2022-3902
https://notcve.org/view.php?id=CVE-2022-3902
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.3 anteriores a 15.4.6, todas las versiones desde 15.5 anteriores a 15.5.5, todas las versiones desde 15.6 anteriores a 15.6.1. Un responsable del proyecto pudo desenmascarar los tokens secretos de los webhooks revisando los registros después de probar los webhooks. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3902.json https://gitlab.com/gitlab-org/gitlab/-/issues/381895 https://hackerone.com/reports/1757999 •
CVE-2022-4092
https://notcve.org/view.php?id=CVE-2022-4092
An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4092.json https://gitlab.com/gitlab-org/gitlab/-/issues/383208 https://hackerone.com/reports/1777934 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •