MEDIUM

CVE-2022-1120

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
6.5

Description

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

Summary dbcve.org

GitLab CE/EE versions prior to 14.7.7, 14.8.5, and 14.9.2 contain a missing input filtering vulnerability in CI/CD error messages. When an include directive fails in the CI/CD configuration, the error message was not properly sanitized, potentially exposing sensitive information such as credentials, tokens, or internal paths that may be present in the pipeline configuration.

Mitigation

Upgrade GitLab to version 14.7.7, 14.8.5, 14.9.2 or later to receive the patch. As a temporary workaround, ensure no sensitive data is present in CI/CD configuration files that could be exposed through error messages.

Weakness (CWE)

CWE-209

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE