HIGH
CVE-2022-0244
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
Summary dbcve.org
Arbitrary file read vulnerability in GitLab CE/EE affecting all versions starting with 14.5. The issue stems from incorrect file handling during group import functionality, allowing authenticated attackers to read arbitrary files on the server file system.
Mitigation
Upgrade GitLab to the latest patched version. If immediate upgrade is not possible, restrict or disable group import functionality for untrusted users as a temporary workaround.
Weakness (CWE)
CWE-552
EPSS Score
1.66%
Probability of exploitation in next 30 days
75.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.