cbcvebase.
CVE-2022-2251
published 2023-01-17

CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who…

PriorityP343high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.17%
63.6th percentile
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiangitlab< gitlab 15.10.8+ds1-2 (sid)gitlab 15.10.8+ds1-2 (sid)
gitlabgitlab
gitlabgitlab_runner
gitlabgitlab_runner
gitlabgitlab_runner
gitlabgitlab_runner
gitlabrunner< 15.3.515.3.5
gitlabrunner>= 15.4.0 < 15.4.415.4.4
gitlabrunner>= 15.5.0 < 15.5.215.5.2

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv8.0HIGH
cisa9.8CRITICAL
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.