MEDIUM
CVE-2022-2228
CVSS
6.5
Description
Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range
Summary dbcve.org
In GitLab EE, IP-based access restrictions on CI variables can be bypassed. An attacker with valid access tokens can retrieve CI variables from groups protected by IP allowlisting, even when the request originates from an IP outside the permitted range.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. Review and rotate any potentially exposed CI variables and access tokens as a precaution.
EPSS Score
0.76%
Probability of exploitation in next 30 days
53.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.