HIGH

CVE-2022-0244

Gitlab GitLab 2022-01-18 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

Summary dbcve.org

Arbitrary file read vulnerability in GitLab CE/EE affecting all versions starting with 14.5. The issue stems from incorrect file handling during group import functionality, allowing authenticated attackers to read arbitrary files on the server file system.

Mitigation

Upgrade GitLab to the latest patched version. If immediate upgrade is not possible, restrict or disable group import functionality for untrusted users as a temporary workaround.

Weakness (CWE)

CWE-552

EPSS Score

1.66%
Probability of exploitation in next 30 days
75.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE