Medium severity4.3NVD Advisory· Published Jan 27, 2023· Updated Jun 17, 2026
CVE-2022-4255
CVE-2022-4255
Description
An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.7.0,<15.4.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.7.0,<15.4.6
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*
- (no CPE)range: from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1
- (no CPE)range: >=13.7, <15.4.6
- Range: from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4255.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/373819nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.