CVE-2022-2229: GitLab
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.
Affected products
- GitLab GitLab: from 13.7.0, before 14.10.5 (fixed in 14.10.5); from 15.0.0, before 15.0.4 (fixed in 15.0.4); version 15.1.0 only
Published 2022-07-01. Last modified 2026-06-17.