CVE-2022-1120: Medium severity gitlab vulnerability
Published Apr 4, 2022
·Updated
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.
Affected Software
6 affected components
GitLab GitLab<14.7.7
GitLab GitLab<14.7.7
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.9.0<14.9.2
GitLab GitLab>=14.9.0<14.9.2
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1120?
CVE-2022-1120 is classified as a high severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2022-1120?
To fix CVE-2022-1120, upgrade GitLab to version 14.7.7, 14.8.5, or 14.9.2 or later.
3
What kind of information is exposed by CVE-2022-1120?
CVE-2022-1120 can expose sensitive configuration data when an include directive fails in CI/CD setups.
4
Which versions of GitLab are affected by CVE-2022-1120?
CVE-2022-1120 affects all versions of GitLab prior to 14.7.7, versions 14.8 before 14.8.5, and 14.9 before 14.9.2.
5
What component of GitLab does CVE-2022-1120 affect?
CVE-2022-1120 affects the GitLab CI/CD configuration due to missing error message filtering.