VulnerabilityModified
CVE-2022-4054
It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.
MEDIUM 5.5EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4054.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/382260Exploit, Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1758126Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4054.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/382260Exploit, Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1758126Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.