CVE-2022-2251
published 2023-01-17CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who…
PriorityP343high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.17%
63.6th percentile
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 15.10.8+ds1-2 (sid) | gitlab 15.10.8+ds1-2 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | runner | < 15.3.5 | 15.3.5 |
| gitlab | runner | >= 15.4.0 < 15.4.4 | 15.4.4 |
| gitlab | runner | >= 15.5.0 < 15.5.2 | 15.5.2 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv8.0HIGH
cisa9.8CRITICAL
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a
vendor_gitlab·2023-01-17·CVSS 4.8
CVE-2022-2251 [MEDIUM] CWE-78 CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a
CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
CISA
Apache Struts Improper Input Validation Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2013-2251 [CRITICAL] CWE-20 Apache Struts Improper Input Validation Vulnerability
Vulnerability: Apache Struts Improper Input Validation Vulnerability
Affected: Apache Struts
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2251
Remediation Due Date: 2022-04-15
Debian
CVE-2022-2251: gitlab - Improper sanitization of branch names in GitLab Runner affecting all versions pr...
vendor_debian·2022·CVSS 4.8
CVE-2022-2251 [MEDIUM] CVE-2022-2251: gitlab - Improper sanitization of branch names in GitLab Runner affecting all versions pr...
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
Scope: local
sid: resolved (fixed in 15.10.8+ds1-2)
OSV
CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15
osv·2023-01-17·CVSS 8.0
CVE-2022-2251 [HIGH] CVE-2022-2251: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
GHSA
GHSA-cxfq-cc8j-j2pp: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15
ghsa_unreviewed·2023-01-17
CVE-2022-2251 [HIGH] CWE-77 GHSA-cxfq-cc8j-j2pp: Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2251.jsonhttps://gitlab.com/gitlab-org/gitlab-runner/-/issues/27386https://hackerone.com/reports/1063511https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2251.jsonhttps://gitlab.com/gitlab-org/gitlab-runner/-/issues/27386https://hackerone.com/reports/1063511
2023-01-17
Published