An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/323552 | Broken Link |
https://hackerone.com/reports/1113405 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/323552 | Broken Link |
https://hackerone.com/reports/1113405 | Permissions Required Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json - Vendor Advisory | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/323552 - Broken Link | |
References | () https://hackerone.com/reports/1113405 - Permissions Required, Third Party Advisory |
Information
Published : 2022-05-11 15:15
Updated : 2024-11-21 06:40
NVD link : CVE-2022-1124
Mitre link : CVE-2022-1124
CVE.ORG link : CVE-2022-1124
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-863
Incorrect Authorization