HIGH

CVE-2022-0751

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
8.8

Description

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

Summary dbcve.org

GitLab CE/EE fails to properly render or sanitize special characters in Snippet file content, allowing attackers to craft malicious snippets that visually misrepresent their nature. This display ambiguity could trick users into believing a file is harmless (e.g., a text file) when it actually contains executable commands or malicious content.

Mitigation

Upgrade GitLab to the patched version; alternatively, disable Snippet creation features until the patch can be applied.

EPSS Score

1.45%
Probability of exploitation in next 30 days
72.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE