CRITICAL

CVE-2022-0735

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
9.8

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

Summary dbcve.org

An information disclosure vulnerability in GitLab's quick actions feature allowed unauthorized users to extract runner registration tokens. The quick actions command processing improperly handled sensitive data, enabling any user to access tokens that could then be used to register malicious runners in projects.

Mitigation

Upgrade GitLab to version 14.6.5, 14.7.4, 14.8.2 or later. Review existing runners for unauthorized registrations and rotate any potentially compromised tokens.

EPSS Score

13.23%
Probability of exploitation in next 30 days
96.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE