CVE-2022-3331
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.
Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 14.5 anteriores a 15.1.6, todas las versiones a partir de 15.2 anteriores a 15.2.4, todas las versiones a partir de 15.3 anteriores a 15.3.2. La integraciĆ³n con Zentao de GitLab presenta una vulnerabilidad de referencia directa a objetos no segura que puede ser explotada por un atacante para filtrar los problemas de los proyectos de Zentao
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-27 CVE Reserved
- 2022-10-17 CVE Published
- 2024-05-09 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/360372 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3331.json | 2022-10-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.5 < 15.1.6 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.5 < 15.1.6" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 15.2 < 15.2.4 Search vendor "Gitlab" for product "Gitlab" and version " >= 15.2 < 15.2.4" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 15.3 < 15.3.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 15.3 < 15.3.2" | enterprise |
Affected
|