CVE-2022-3375 is a low-severity information disclosure vulnerability affecting GitLab versions 11.10 through 15.8.5, 15.9 through 15.9.4, and 15.10 through 15.10.1. An attacker with a fork of a project could disclose branch names even after the original project was made private. The CVSS score is 3.7 (LOW), indicating a network-based attack with high complexity and low impact on confidentiality. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. While there is minimal community discussion and media coverage, GitLab has released security updates to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.10.0, < 15.8.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.10.0, < 15.8.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.9.0, < 15.9.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.9.0, < 15.9.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
15.10.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.