Medium severity4.3NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026
CVE-2022-3351
CVE-2022-3351
Description
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.7.0,<15.2.5
- (no CPE)range: from 13.7 before 15.2.5, from 15.3 before 15.3.4, from 15.4 before 15.4.1
- (no CPE)range: >=15.4, <15.4.1
- Range: from 13.7 before 15.2.5, from 15.3 before 15.3.4, from 15.4 before 15.4.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3351.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/364266nvdBroken LinkVendor Advisory
- hackerone.com/reports/1446022nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.