CVE-2022-4255 is an information leakage vulnerability affecting GitLab Enterprise Edition versions 13.7 through 15.4.5, 15.5 through 15.5.4, and 15.6 through 15.6.0. This flaw exposes user email IDs through webhook payloads, potentially revealing sensitive user information. Rated Medium severity with a CVSS score of 5.3, it requires no user interaction or privileges to exploit, and its impact is limited to confidentiality. There is no evidence of active exploitation, nor is public exploit code available, and it has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.7.0, < 15.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 13.7.0, < 15.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.5.0, < 15.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.5.0, < 15.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
15.6.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.