PT-2022-12973 · Gitlab · Gitlab

Ngo Wei Lin

·

Published

2022-01-18

·

Updated

2024-03-06

·

CVE-2022-0090

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 14.4.5 GitLab versions 14.5.0 through 14.5.3 GitLab versions 14.6.0 through 14.6.1
Description An issue has been discovered in GitLab where it does not ignore replacement references with git sub-commands. This allows a malicious user to spoof the contents of their commits in the UI.
Recommendations For versions prior to 14.4.5, update to version 14.4.5 or later. For versions 14.5.0 through 14.5.3, update to version 14.5.4 or later. For versions 14.6.0 through 14.6.1, update to version 14.6.2 or later.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-0090
CVE-2022-0090

Affected Products

Gitlab