MEDIUM

CVE-2022-0123

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
6.8

Description

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

Summary dbcve.org

GitLab versions prior to 14.4.5, between 14.5.0-14.5.3, and between 14.6.0-14.6.1 fail to validate SSL certificates when connecting to certain external CI services, allowing attackers on the network path to intercept and potentially modify traffic via Man-in-the-Middle attacks.

Mitigation

Upgrade GitLab to version 14.4.5, 14.5.3, 14.6.1 or later. For self-managed instances, plan a maintenance window and ensure backups before performing the upgrade.

Weakness (CWE)

CWE-295 Improper Certificate Validation

EPSS Score

0.44%
Probability of exploitation in next 30 days
37.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE