CVE-2022-2531
Description
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability.
Summary dbcve.org
A path traversal vulnerability in GitLab EE allows unauthenticated users to make Grafana API queries due to improper authentication checks on the Grafana integration. An attacker can manipulate API paths to bypass authentication and access sensitive monitoring data.
Mitigation
Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1, or later. Alternatively, if immediate upgrade is not feasible, disable or restrict the Grafana integration until patching can be completed.