QID 379232
Date Published: 2024-01-16
QID 379232: GitLab EE/CE Improper Authorization Vulnerability (CVE-2022-1545)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2022-1545: It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting, if an unauthorised project member was tagged in the note.
Affected Versions:
Gitlab CE/EE all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows disclosure of pipeline status to unauthorized users.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
- CVE-2022-1545 -
gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json
CVEs related to QID 379232
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-1545 |
|