QID 376655
Date Published: 2022-06-06
QID 376655: GitLab Multiple Security Vulnerabilities (gitlab- 15.0.1, 14.10.4, and 14.9.5)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
Affected Version:
All versions from 10.8 prior to 14.9.5
All versions from 14.10 prior to 14.10.4
All versions from 15.0 prior to 15.0.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of these vulnerabilities may lead to:
CVE-2022-1680: Account take over via SCIM email change
CVE-2022-1940: Stored XSS in Jira integration
CVE-2022-1948: Quick action commands susceptible to XSS
CVE-2022-1935: IP allowlist bypass when using Trigger tokens
CVE-2022-1936: IP allowlist bypass when using Project Deploy Tokens
CVE-2022-1944: Improper authorization in the Interactive Web Terminal
CVE-2022-1821: Subgroup member can list members of parent group
CVE-2022-1783: Group member lock bypass
CVEs related to QID 376655
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Gitlab-Advisory |
|