CVE-2022-4342 is a low-severity vulnerability in GitLab CE/EE versions 15.1 through 15.5.6, 15.6 through 15.6.3, and 15.7 through 15.7.1. A malicious Maintainer can exploit this flaw by altering a webhook's target URL to expose masked webhook secrets. The attack requires high privileges (PR:H) and has low impact on confidentiality and integrity (C:L/I:L), with no impact on availability. There is no public exploit code available, nor is it listed on the KEV catalog, indicating no active exploitation. However, the vulnerability has garnered some community discussion and media coverage, primarily from GitLab's security releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.1.0, < 15.5.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.1.0, < 15.5.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.6.0, < 15.6.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.6.0, < 15.6.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.7.0, < 15.7.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.