Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.
CVSS Details
- CVSS 3.1 Base Score: 5.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade gitlab-ce | Nov 4, 2022 | Mar 9, 2022 |
| Gitlab | — | Upgrade to Gitlab v14.6.5Upgrade to Gitlab v14.8.2Upgrade to Gitlab v14.7.4 | Mar 1, 2022 | Feb 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub