An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/323552 | Broken Link |
https://hackerone.com/reports/1113405 | Permissions Required Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitLab
Published: 2022-05-11T14:50:29
Updated: 2022-05-11T14:50:29
Reserved: 2022-03-28T00:00:00
Link: CVE-2022-1124
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-05-11T15:15:08.713
Modified: 2022-05-18T20:28:44.310
Link: CVE-2022-1124
JSON object: View
Redhat Information
No data.
CWE