6.1
CVSSv3

CVE-2022-0167

Published: 01/07/2022 Updated: 13/07/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.4.5, all versions starting from 14.5.0 prior to 14.5.3, all versions starting from 14.6.0 prior to 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab