First published: Tue Jan 18 2022(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=14.5<=14.5.3 | |
GitLab | >=14.5<=14.5.3 | |
GitLab | >=14.6<=14.6.2 | |
GitLab | >=14.6<=14.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0244 is considered a high severity vulnerability due to the potential for arbitrary file read access.
To fix CVE-2022-0244, upgrade GitLab to version 14.5.4 or later for versions 14.5.x and to version 14.6.3 or later for versions 14.6.x.
CVE-2022-0244 affects all GitLab Community Edition and Enterprise Edition versions starting from 14.5 to 14.6.2.
CVE-2022-0244 allows for arbitrary file reading, which can lead to unauthorized access to sensitive files.
There is no official workaround for CVE-2022-0244; upgrading to the patched versions is recommended.