HIGH
CVE-2022-1423
CVSS
8.8
Description
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches
Summary dbcve.org
Improper access control in GitLab's CI/CD cache mechanism allows a Developer-level user to poison the cache, which can then lead to arbitrary code execution in protected branches that should normally require higher privileges.
Mitigation
Upgrade GitLab to version 14.8.6, 14.9.4, 14.10.1 or later. Additionally, review CI/CD pipeline configurations and audit Developer-level accounts for suspicious activity.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
1.45%
Probability of exploitation in next 30 days
72.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.