HIGH
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5
Published Jan 18, 2022
8.6
HIGHCVSS 3.1
EPSS 1.66%
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
Affected products
-
Affected
- ≥ 14.5, < 14.5.3
- ≥ 14.6, < 14.6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15437 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.json x_refsource_CONFIRMVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/349524 x_refsource_MISCBroken LinkVendor Advisory
- https://hackerone.com/reports/1439593 x_refsource_MISCPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15437 | Advisory | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.json | x_refsource_CONFIRMVendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/349524 | x_refsource_MISCBroken LinkVendor Advisory | |
| https://hackerone.com/reports/1439593 | x_refsource_MISCPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jan 18, 2022
Updated Aug 2, 2024
Reserved Jan 16, 2022
Link CVE-2022-0244
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data