CVE-2022-1120
Description
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.
Summary dbcve.org
GitLab CE/EE versions prior to 14.7.7, 14.8.5, and 14.9.2 contain a missing input filtering vulnerability in CI/CD error messages. When an include directive fails in the CI/CD configuration, the error message was not properly sanitized, potentially exposing sensitive information such as credentials, tokens, or internal paths that may be present in the pipeline configuration.
Mitigation
Upgrade GitLab to version 14.7.7, 14.8.5, 14.9.2 or later to receive the patch. As a temporary workaround, ensure no sensitive data is present in CI/CD configuration files that could be exposed through error messages.