Medium severity6.5NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026
CVE-2022-3291
CVE-2022-3291
Description
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.9,<15.2.5
- (no CPE)range: >=14.9, <15.2.5
- Range: from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3291.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/354299nvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.