HIGH
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1
Published Mar 28, 2022
8.1
HIGHCVSS 3.1
EPSS 0.97%
Description
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
Affected products
-
- Version >=10.5, <14.5.4StatusaffectedConstraints-
- Version >=14.6, <14.6.4StatusaffectedConstraints-
- Version >=14.7, <14.7.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0136.json x_refsource_CONFIRMVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/28561 x_refsource_MISCBroken Link
- https://hackerone.com/reports/560658 x_refsource_MISCPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0136.json | x_refsource_CONFIRMVendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/28561 | x_refsource_MISCBroken Link | |
| https://hackerone.com/reports/560658 | x_refsource_MISCPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 28, 2022
Updated Aug 2, 2024
Reserved Jan 6, 2022
Link CVE-2022-0136
CISA Vulnrichment
Updated n/a