CVE-2022-3060 is a high-severity vulnerability in GitLab CE/EE, affecting all versions from 12.7, where an improper control of a resource identifier in the Error Tracking feature allows an authenticated attacker to craft content that could lead a victim to make unintended arbitrary requests. With a CVSS score of 7.3, this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality and integrity, though no impact on availability. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received minimal community discussion and media coverage, GitLab has released security updates to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.7.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
<= 12.7.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.