VulnerabilityModified
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
MEDIUM 4.3EPSS 0.76%
Does this matter?
Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.
Description
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1105.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/335933Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1105.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/335933Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.