« Volver al listado

CVE-2022-1545

Estado: ModificadaMedia (4.3)—

Era posible divulgar detalles de notas confidenciales creadas por medio de la API en Gitlab CE/EE, afectando a todas las versiones desde la 13.2 hasta la 14.8.6, 14.9 anteriores a 14.9.4 y 14.10 anteriores a 14.10.1, si un miembro del proyecto no autorizado era etiquetado en la nota

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1545",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": ">=13.2, <14.8.6"
            },
            {
              "status": "affected",
              "version": ">=14.9, <14.9.4"
            },
            {
              "status": "affected",
              "version": ">=14.10, <14.10.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-11T15:15:09.180",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/351030",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/351030",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note."
    },
    {
      "lang": "es",
      "value": "Era posible divulgar detalles de notas confidenciales creadas por medio de la API en Gitlab CE/EE, afectando a todas las versiones desde la 13.2 hasta la 14.8.6, 14.9 anteriores a 14.9.4 y 14.10 anteriores a 14.10.1, si un miembro del proyecto no autorizado era etiquetado en la nota"
    }
  ],
  "lastModified": "2026-06-17T04:22:38.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BE2CE33-FF2B-4655-99F0-45F8E85F6C88",
              "versionEndExcluding": "14.8.6",
              "versionStartIncluding": "13.2.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A145FE4C-CEB0-4A95-94C8-612F6763D5F9",
              "versionEndExcluding": "14.8.6",
              "versionStartIncluding": "13.2.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCD83B23-0868-4545-9E4E-98F0DF151924",
              "versionEndExcluding": "14.9.4",
              "versionStartIncluding": "14.9.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B4C393E-6B88-4AF8-9071-2C43935A1AEC",
              "versionEndExcluding": "14.9.4",
              "versionStartIncluding": "14.9.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41411D82-66AE-4AE4-9093-D019F80ED990"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9643D908-345C-48F9-BEDE-08F69EC16931"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}