Loading HuntDB...

GHSA-v4qw-4358-7wh4

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

Related CVEs

Key Information

GHSA ID
GHSA-v4qw-4358-7wh4
Published
December 14, 2021 12:00 AM
Last Modified
December 17, 2021 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 17, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.