April 5, 2023, 9:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

addresses cve fix gitlab issue leak parameter secrets url webhook

Application Security Assurance Associate

@ DTCC | Tampa, FL, United States

Threat Hunter II

@ Microsoft | Hyderabad, Telangana, India

Staff Cyber Security Engineer (Application Security, Emerging Platforms)

@ NBCUniversal | Englewood Cliffs, NEW JERSEY, United States

Cyber Security Senior Cyber Security Engineer

@ Sopra Steria | Noida, Uttar Pradesh, India

Data Protection and Privacy Manager

@ Future PLC | London, England, United Kingdom

RSOC Manager

@ The University of Texas at Austin | AUSTIN, TX