CVE-2022-1124 — Incorrect Authorization in Gitlab
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 52.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 12
Description
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-fcmm-jq9f-cc5p: An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14↗2022-05-12
📋Vendor Advisories
2GitLab▶
CVE-2022-1124: An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4,↗2022-05-11
Debian▶
CVE-2022-1124: gitlab - An improper authorization issue has been discovered in GitLab CE/EE affecting al...↗2022