← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-0735

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

Nuclei Template
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:13.23%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
GitLab GitLab >=14.8, <14.8.2 (affected), >=14.7, <14.7.4 (affected), >=12.10, <14.6.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
13.227%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitLab Inc. · Vendor · USA
Reserved2022-02-23T00:00:00
Published2022-03-28T18:52:59
Last Updated2024-08-02T23:40:03

LINK COPIED TO CLIPBOARD