QID 379231
Date Published: 2024-01-31
QID 379231: GitLab Multiple Security Vulnerabilities (gitlab- 15.3.2, 15.2.4 and 15.1.6)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2022-4255: n improper access control issue in GitLab CE/EE affecting, allows disclosure of pipeline status to unauthorized users.
Affected Versions:
GitLab CE/EE all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows disclosure of pipeline status to unauthorized users.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
- CVE-2022-3030 -
gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3030.json - GitLab Critical Security Release: 15.3.2, 15.2.4 and 15.1.6 -
about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/
CVEs related to QID 379231
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-3030 |
|