CVE-2022-1944Incorrect Authorization in Gitlab

Severity
7.1HIGHNVD
EPSS
0.2%
top 62.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateOct 21

Description

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages5 packages

NVDgitlab/gitlab11.3.014.9.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=11.3, <14.9.5, >=14.10, <14.10.4, >=15.0, <15.0.1+2
gitlabgitlab/gitlab

Patches

🔴Vulnerability Details

1
GHSA
GHSA-2wrv-52w9-gffw: When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 112022-06-07

📋Vendor Advisories

3
Red Hat
kernel: mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()2024-10-21
GitLab
CVE-2022-1944: When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.2022-06-06
Debian
CVE-2022-1944: gitlab - When the feature is configured, improper authorization in the Interactive Web Te...2022