PT-2022-12977 · Gitlab · Gitlab

Published

2022-03-28

·

Updated

2024-03-06

·

CVE-2022-0123

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 14.4.5 GitLab versions 14.5.0 through 14.5.3 GitLab versions 14.6.0 through 14.6.1
Description An issue has been discovered where GitLab does not validate SSL certificates for some external CI services, making it possible to perform Man-in-the-Middle (MitM) attacks on connections to these external services.
Recommendations For versions prior to 14.4.5, update to version 14.4.5 or later. For versions 14.5.0 through 14.5.3, update to version 14.5.4 or later. For versions 14.6.0 through 14.6.1, update to version 14.6.2 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-0123
CVE-2022-0123

Affected Products

Gitlab