When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json | Patch Third Party Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/349750 | Broken Link |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitLab
Published: 2022-06-06T16:58:35
Updated: 2022-06-06T16:58:35
Reserved: 2022-05-30T00:00:00
Link: CVE-2022-1944
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-06T17:15:10.867
Modified: 2022-06-13T18:37:12.907
Link: CVE-2022-1944
JSON object: View
Redhat Information
No data.
CWE