An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/323552 | Broken Link |
https://hackerone.com/reports/1113405 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-05-11 08:15
Updated : 2022-05-18 13:28
NVD link : CVE-2022-1124
Mitre link : CVE-2022-1124
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
gitlab
- gitlab