QID 376714
Date Published: 2022-07-04
QID 376714: GitLab Multiple Security Vulnerabilities (gitlab - 15.1.1, 15.0.4, and 14.10.5)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
Affected Version:
All versions from 1.0.2 prior to 14.10.5
All versions from 15.0 prior to 15.0.4
All versions from 15.1 prior to 15.1.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of these vulnerabilities may lead to:
CVE-2022-2185: Remote Command Execution via Project Imports
CVE-2022-2235: XSS in ZenTao integration affecting self hosted instances without strict CSP
CVE-2022-2230: XSS in project settings page
CVE-2022-2229: Unallowed users can read unprotected CI variables
CVE-2022-1983: IP allow-list bypass to access Container Registries
CVE-2022-1963: 2FA status is disclosed to unauthenticated users
CVE-2022-1981: Restrict membership by email domain bypass
CVE-2022-2243: IDOR in sentry issues
CVE-2022-2244: Reporters can manage issues in error tracking
CVE-2022-2228: CI variables provided to runners outside of a group's restricted IP range
CVE-2022-1954: Regular Expression Denial of Service via malicious web server responses
CVE-2022-2270: Unauthorized read for conan repository
CVE-2022-2250: Open redirect vulnerability
CVE-2022-1999: Group labels are editable through subproject
CVE-2022-2281: Release titles visible for any users if group milestones are associated with any project releases
CVE-2022-2227: Job information is leaked to users who previously were maintainers via the Runner Jobs API endpoint
CVEs related to QID 376714
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Gitlab-Advisory |
|