QID 376482
Date Published: 2022-03-24
QID 376482: GitLab Multiple Security Vulnerabilities (gitlab- 14.8.2, 14.7.4, 14.6.5)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
The GitLab update fixes the following vulnerabilities:
CVE-2022-0735: An unauthorized user can steal runner registration tokens using an information disclosure vulnerability by using quick commands.
CVE-2022-0741: An unauthorized user can steal environment variables using specially crafted email addresses due to improper input validation in sendmail.
CVE-2022-0751 An unauthorized user can trick users into executing arbitrary commands due to inaccurate display of Snippet files with special characters.
Affected Version:
All versions from 12.10 prior to 14.6.5
All versions from 14.7 prior to 14.7.4
All versions from 14.8 prior to 14.8.2
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of these vulnerabilities may allow either an unauthorized attacker to trick other users into executing arbitrary commands or expose sensitive information.
CVEs related to QID 376482
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Gitlab-Advisory |
|