MEDIUM

CVE-2022-0172

Gitlab GitLab 2022-01-18 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

Summary dbcve.org

GitLab CE/EE versions 12.3 and later contained a vulnerability where IP restrictions intended for public projects could be bypassed through the GraphQL API. This allowed unauthenticated attackers to read the titles of issues, merge requests, and milestones that should have been restricted based on IP whitelisting rules.

Mitigation

Upgrade GitLab to a patched version (refer to GitLab's official security release for version-specific patches). After upgrading, verify that IP restriction policies are properly enforced for GraphQL API endpoints.

EPSS Score

0.77%
Probability of exploitation in next 30 days
53.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE