MEDIUM

CVE-2022-1406

Gitlab GitLab 2022-05-11 CVSS v3.1
CVSS
6.5

Description

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

Summary dbcve.org

Improper input validation in GitLab CE/EE allows a Developer to bypass restrictions on protected CI/CD variables by importing a malicious project. Protected variables containing sensitive secrets (API keys, tokens, credentials) can be read by users with Developer permissions who should not have access to these protected values.

Mitigation

Upgrade GitLab to version 14.8.6, 14.9.4, or 14.10.1 or later to patch the input validation vulnerability in the project import functionality.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

1.14%
Probability of exploitation in next 30 days
65.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE