CVE-2022-2227: Medium severity gitlab vulnerability
Published Jul 1, 2022
·Updated
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
Affected Software
6 affected components
GitLab GitLab<14.10.5
GitLab GitLab<14.10.5
GitLab GitLab>=15.0.0<15.0.4
GitLab GitLab>=15.0.0<15.0.4
GitLab GitLab=15.1.0
GitLab GitLab=15.1.0
Event History
Jul 1, 2022
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2227?
CVE-2022-2227 has a medium severity due to improper access control vulnerabilities.
2
How do I fix CVE-2022-2227?
To fix CVE-2022-2227, upgrade GitLab to version 14.10.5, 15.0.4, or 15.1.1 or later.
3
Who is affected by CVE-2022-2227?
CVE-2022-2227 affects all versions of GitLab prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1.
4
What types of information can be accessed due to CVE-2022-2227?
Due to CVE-2022-2227, unauthorized users can access job and project metadata.
5
What software versions should be updated to address CVE-2022-2227?
Update GitLab community and enterprise versions to 14.10.5, 15.0.4, or 15.1.1 to address CVE-2022-2227.