Medium severity5.4NVD Advisory· Published May 19, 2022· Updated Jun 17, 2026
CVE-2022-1413
CVE-2022-1413
Description
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=1.0.2,<14.8.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=1.0.2,<14.8.6
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=1.0.2, <14.8.6
- Range: 1.0.2 <= v < 14.8.6, 14.9.0 <= v < 14.9.4, 14.10.0 <= v < 14.10.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1413.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/353720nvdBroken Link
News mentions
0No linked articles in our index yet.