PT-2022-3034 · Gitlab · Gitlab Ce/Ee+1

Published

2022-05-30

·

Updated

2024-03-06

·

CVE-2022-1935

CVSS v2.0

7.9

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab Enterprise Edition versions 12.0 through 14.9.4 GitLab Enterprise Edition versions 14.10.0 through 14.10.3 GitLab Enterprise Edition versions 15.0.0
Description The issue is related to incorrect authorization in GitLab Enterprise Edition, allowing an attacker with a valid Project Trigger Token to bypass security restrictions from any location, even when IP address restrictions are configured.
Recommendations For versions 12.0 through 14.9.4, update to version 14.9.5 or later. For versions 14.10.0 through 14.10.3, update to version 14.10.4 or later. For version 15.0.0, update to version 15.0.1 or later.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-03702
BIT-GITLAB-2022-1935
CVE-2022-1935

Affected Products

Gitlab
Gitlab Ce/Ee