PT-2022-2255 · Gitlab · Gitlab Ce/Ee+1
Published
2022-02-25
·
Updated
2026-05-26
·
CVE-2022-0735
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 12.10 through 14.6.4
GitLab CE/EE versions 14.7 through 14.7.3
GitLab CE/EE versions 14.8 through 14.8.1
Description
An issue has been discovered in GitLab CE/EE, allowing an unauthorized user to steal runner registration tokens through an information disclosure vulnerability using quick actions commands. The vulnerability is related to deficiencies in the authorization mechanism, which can be exploited by a remote attacker to gain unauthorized access to protected information using specially crafted commands. The issue is caused by an information leak when using Quick Actions commands.
Recommendations
For GitLab CE/EE versions 12.10 through 14.6.4, update to version 14.6.5 or later.
For GitLab CE/EE versions 14.7 through 14.7.3, update to version 14.7.4 or later.
For GitLab CE/EE versions 14.8 through 14.8.1, update to version 14.8.2 or later.
As a temporary workaround, consider restricting access to Quick Actions commands until a patch is available.
Exploit
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee