PT-2022-2255 · Gitlab · Gitlab Ce/Ee+1

Published

2022-02-25

·

Updated

2026-05-26

·

CVE-2022-0735

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.10 through 14.6.4 GitLab CE/EE versions 14.7 through 14.7.3 GitLab CE/EE versions 14.8 through 14.8.1
Description An issue has been discovered in GitLab CE/EE, allowing an unauthorized user to steal runner registration tokens through an information disclosure vulnerability using quick actions commands. The vulnerability is related to deficiencies in the authorization mechanism, which can be exploited by a remote attacker to gain unauthorized access to protected information using specially crafted commands. The issue is caused by an information leak when using Quick Actions commands.
Recommendations For GitLab CE/EE versions 12.10 through 14.6.4, update to version 14.6.5 or later. For GitLab CE/EE versions 14.7 through 14.7.3, update to version 14.7.4 or later. For GitLab CE/EE versions 14.8 through 14.8.1, update to version 14.8.2 or later. As a temporary workaround, consider restricting access to Quick Actions commands until a patch is available.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02363
BIT-GITLAB-2022-0735
CVE-2022-0735

Affected Products

Gitlab
Gitlab Ce/Ee