HIGH

CVE-2022-4138

Gitlab GitLab 2023-02-13 CVSS v3.1
CVSS
8.1

Description

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

Summary dbcve.org

A Cross-Site Request Forgery (CSRF) vulnerability in GitLab CE/EE allows attackers to exploit file upload functionality. Attackers can trick authenticated Owner or Maintainer users into uploading files to malicious projects by leveraging the lack of proper CSRF token validation on file upload endpoints, potentially leading to complete project takeover.

Mitigation

Upgrade GitLab to version 15.6.7, 15.7.6, or 15.8.1 or later. These versions implement proper CSRF protection for file upload operations.

Weakness (CWE)

CWE-352 Cross-Site Request Forgery (CSRF)

EPSS Score

0.45%
Probability of exploitation in next 30 days
38.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE