HIGH

CVE-2022-0741

Gitlab GitLab 2022-04-01 CVSS v3.1
CVSS
7.5

Description

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

Summary dbcve.org

Improper input validation in GitLab CE/EE's sendmail email functionality allows attackers to inject specially crafted email addresses that can extract environment variables from the GitLab process, potentially exposing sensitive configuration data, API keys, and credentials.

Mitigation

Upgrade GitLab to the patched version addressing CVE-2022-0741; if immediate upgrade is not feasible, consider disabling sendmail-based email delivery or implementing additional input sanitization at the mail transfer agent level.

Weakness (CWE)

CWE-116

EPSS Score

1.48%
Probability of exploitation in next 30 days
72.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE