First published: Fri Aug 05 2022(Updated: )
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.5.0<15.0.5 | |
GitLab | >=15.1.0<15.1.4 | |
GitLab | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2531 is classified as a medium severity vulnerability.
To fix CVE-2022-2531, upgrade your GitLab EE installation to version 15.0.5, 15.1.4, or 15.2.1 or later.
CVE-2022-2531 affects GitLab EE versions from 12.5 up to, but not including, 15.0.5, 15.1 up to 15.1.4, and 15.2 up to 15.2.1.
CVE-2022-2531 is associated with improper authentication on the Grafana API.
No official workaround is provided for CVE-2022-2531; upgrading to a patched version is recommended.