CVE-2022-1148
Description
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites
Summary dbcve.org
Improper authorization in GitLab Pages allows an attacker controlling a private Pages site to steal a victim's access token when the user visits, then reuse that token to access the victim's other private Pages sites. The vulnerability stems from insufficient validation of authorization boundaries between private Pages sites.
Mitigation
Upgrade GitLab to version 14.7.7, 14.8.5, or 14.9.2 or later to patch the authorization flaw in GitLab Pages.