PT-2022-13670 · Gitlab · Gitlab Ce/Ee+1

Published

2022-04-04

·

Updated

2024-03-06

·

CVE-2022-1120

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 14.7.7 GitLab CE/EE versions 14.8 prior to 14.8.5 GitLab CE/EE versions 14.9 prior to 14.9.2
Description The issue concerns missing filtering in an error message, which exposes sensitive information when an include directive fails in the CI/CD configuration. This affects all versions prior to the specified fixed versions.
Recommendations For versions prior to 14.7.7, update to version 14.7.7 or later. For versions 14.8 prior to 14.8.5, update to version 14.8.5 or later. For versions 14.9 prior to 14.9.2, update to version 14.9.2 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1120
CVE-2022-1120

Affected Products

Gitlab
Gitlab Ce/Ee