VYPR
Medium severity6.5NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026

CVE-2022-3291

CVE-2022-3291

Description

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

Affected products

4
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.9,<15.2.5
    • (no CPE)range: >=14.9, <15.2.5
  • Range: from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
  • osv-coords
    Range: >= 14.9.0, < 15.2.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.