MEDIUM

CVE-2022-1148

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
6.5

Description

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

Summary dbcve.org

Improper authorization in GitLab Pages allows an attacker controlling a private Pages site to steal a victim's access token when the user visits, then reuse that token to access the victim's other private Pages sites. The vulnerability stems from insufficient validation of authorization boundaries between private Pages sites.

Mitigation

Upgrade GitLab to version 14.7.7, 14.8.5, or 14.9.2 or later to patch the authorization flaw in GitLab Pages.

Weakness (CWE)

CWE-565

EPSS Score

1.18%
Probability of exploitation in next 30 days
66.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE