MEDIUM

CVE-2022-2531

Gitlab GitLab 2022-08-05 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability.

Summary dbcve.org

A path traversal vulnerability in GitLab EE allows unauthenticated users to make Grafana API queries due to improper authentication checks on the Grafana integration. An attacker can manipulate API paths to bypass authentication and access sensitive monitoring data.

Mitigation

Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1, or later. Alternatively, if immediate upgrade is not feasible, disable or restrict the Grafana integration until patching can be completed.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.33%
Probability of exploitation in next 30 days
69.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE