HIGH

CVE-2022-1423

Gitlab GitLab 2022-05-19 CVSS v3.1
CVSS
8.8

Description

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

Summary dbcve.org

Improper access control in GitLab's CI/CD cache mechanism allows a Developer-level user to poison the cache, which can then lead to arbitrary code execution in protected branches that should normally require higher privileges.

Mitigation

Upgrade GitLab to version 14.8.6, 14.9.4, 14.10.1 or later. Additionally, review CI/CD pipeline configurations and audit Developer-level accounts for suspicious activity.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

1.45%
Probability of exploitation in next 30 days
72.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE