PT-2022-13673 · Gitlab · Gitlab Ce/Ee+1

Jimenoon

·

Published

2022-05-11

·

Updated

2024-03-06

·

CVE-2022-1124

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 14.8.6 GitLab CE/EE versions 14.9.0 through 14.9.4 GitLab CE/EE version 14.10.0
Description An improper authorization issue has been discovered, allowing Guest project members to access the trace log of jobs when it is enabled.
Recommendations For versions prior to 14.8.6, update to version 14.8.6 or later. For versions 14.9.0 through 14.9.3, update to version 14.9.4 or later. For version 14.10.0, update to a version later than 14.10.0.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1124
CVE-2022-1124

Affected Products

Gitlab
Gitlab Ce/Ee