CVE-2022-0751Gitlab vulnerability

5 documents5 sources
Severity
8.8HIGHNVD
EPSS
0.3%
top 50.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMar 29

Description

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

NVDgitlab/gitlab10.014.6.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=10.0, <14.6.5, >=14.7, <14.7.4, >=14.8, <14.8.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-x34v-2x5g-pxw5: Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleadin2022-03-29
OSV
CVE-2022-0751: Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleadin2022-03-28

📋Vendor Advisories

2
GitLab
CVE-2022-0751: Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleadin2022-03-28
Debian
CVE-2022-0751: gitlab - Inaccurate display of Snippet files containing special characters in all version...2022