CVE-2022-1406: Input Validation
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1406?
CVE-2022-1406 has a medium severity rating due to improper input validation allowing unauthorized access to protected CI/CD variables.
How do I fix CVE-2022-1406?
To remediate CVE-2022-1406, upgrade to GitLab version 14.8.6 or later, or 14.9.4 and above for affected versions.
Who is affected by CVE-2022-1406?
CVE-2022-1406 affects all versions of GitLab CE/EE from 8.12 up to 14.8.6, versions from 14.9.0 up to 14.9.4, and version 14.10.0.
What kind of vulnerability is CVE-2022-1406?
CVE-2022-1406 is categorized as an improper input validation vulnerability.
What impact does CVE-2022-1406 have on my GitLab projects?
CVE-2022-1406 allows unauthorized developers to read protected Group or Project CI/CD variables by importing a malicious project.