CVE-2022-1105: Medium severity gitlab vulnerability
Published Apr 4, 2022
·Updated
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
Affected Software
6 affected components
GitLab GitLab>=13.11.0<14.7.7
GitLab GitLab>=13.11.0<14.7.7
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.9.0<14.9.2
GitLab GitLab>=14.9.0<14.9.2
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-1105.
2
What is the severity of CVE-2022-1105?
The severity of CVE-2022-1105 is medium with a score of 4.3.
3
Which versions of GitLab are affected by CVE-2022-1105?
All versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 are affected.
4
What is the impact of CVE-2022-1105?
The vulnerability allows an unauthorized user to access pipeline analytics even when public pipelines are disabled.
5
Is there a fix available for CVE-2022-1105?
Yes, GitLab has released fixes for this vulnerability in versions 14.7.7, 14.8.5, and 14.9.2.