VYPR
Medium severity5.7NVD Advisory· Published Jan 17, 2023· Updated Jun 17, 2026

CVE-2022-2907

CVE-2022-2907

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

Affected products

6
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.9,<15.1.6
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.9,<=15.1.6
    • (no CPE)range: 12.9 <= v < 15.1.6, 15.2 <= v < 15.2.4, 15.3 <= v < 15.3.2
    • (no CPE)range: >=12.9, <15.1.6
  • Range: 12.9 <= v < 15.1.6, 15.2 <= v < 15.2.4, 15.3 <= v < 15.3.2
  • osv-coords
    Range: >= 12.9.0, < 15.1.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.