PT-2022-13904 · Gitlab · Gitlab

Published

2022-05-11

·

Updated

2024-03-06

·

CVE-2022-1460

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 9.2 through 14.8.5 GitLab versions 14.9 through 14.9.3 GitLab versions 14.10 through 14.10.0
Description An issue has been discovered in GitLab where it was not performing correct authorizations on scheduled pipelines. This allowed a malicious user to run a pipeline in the context of another user.
Recommendations For versions 9.2 through 14.8.5, update to version 14.8.6 or later. For versions 14.9 through 14.9.3, update to version 14.9.4 or later. For versions 14.10 through 14.10.0, update to version 14.10.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1460
CVE-2022-1460

Affected Products

Gitlab