Medium severity5.0NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2022-4343
CVE-2022-4343
Description
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.12
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.12,<16.1.5
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
- Range: starting from 13.12 before 16.1.5, starting from 16.2 before 16.2.5, starting from 16.3 before 16.3.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/385124nvdBroken Link
- hackerone.com/reports/1767797nvdPermissions Required
News mentions
1- GitLab Security Release: 16.3.1, 16.2.5, and 16.1.5GitLab Security Releases · Aug 31, 2023