MEDIUM
CVE-2022-1406
CVSS
6.5
Description
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
Summary dbcve.org
Improper input validation in GitLab CE/EE allows a Developer to bypass restrictions on protected CI/CD variables by importing a malicious project. Protected variables containing sensitive secrets (API keys, tokens, credentials) can be read by users with Developer permissions who should not have access to these protected values.
Mitigation
Upgrade GitLab to version 14.8.6, 14.9.4, or 14.10.1 or later to patch the input validation vulnerability in the project import functionality.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
1.14%
Probability of exploitation in next 30 days
65.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.