CVE-2022-2095: Medium severity gitlab vulnerability
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2095?
CVE-2022-2095 has a medium severity due to improper access control allowing unauthorized information disclosure.
How do I fix CVE-2022-2095?
To fix CVE-2022-2095, upgrade GitLab to version 15.0.5 or later, 15.1.4 or later, or 15.2.1 or later.
Which versions of GitLab are affected by CVE-2022-2095?
CVE-2022-2095 affects all versions of GitLab CE/EE starting from 13.7 before 15.0.5 and from 15.1 before 15.1.4, and from 15.2 before 15.2.1.
What type of vulnerability is CVE-2022-2095?
CVE-2022-2095 is classified as an improper access control vulnerability.
Can a non-authenticated user exploit CVE-2022-2095?
No, CVE-2022-2095 can only be exploited by a malicious authenticated user.