Improper Access Control in GitLab CE/EE: Confidential Information Disclosure via Incident Timeline Events

Improper Access Control in GitLab CE/EE: Confidential Information Disclosure via Incident Timeline Events

CVE-2022-2630 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

Learn more about our Web Application Penetration Testing UK.