CVE-2022-1148: Medium severity gitlab vulnerability
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1148?
CVE-2022-1148 is classified as a high severity vulnerability due to its potential for unauthorized access and token theft.
How does CVE-2022-1148 affect GitLab users?
CVE-2022-1148 allows attackers to steal a user's access token from an attacker-controlled private GitLab Pages site.
How do I fix CVE-2022-1148?
To address CVE-2022-1148, GitLab users should upgrade to version 14.7.7, 14.8.5, or 14.9.2 or later.
Which versions of GitLab are affected by CVE-2022-1148?
CVE-2022-1148 affects all versions of GitLab CE/EE from 11.5 to prior versions of 14.7.7, 14.8.5, and 14.9.2.
What are the potential impacts of CVE-2022-1148?
The potential impact of CVE-2022-1148 includes unauthorized access to sensitive user data and the ability to manipulate projects on GitLab.