CVE-2022-4342
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.
- CVSS Version 3.1
nvd
CVE ID: CVE-2022-4342
Base Score: 3.8
Base Severity: LOW
Vector String:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Impact Score: 2.5
Exploitability Score: 1.2
gitlab
CVE ID: CVE-2022-4342
Base Score: 5.5
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3