CVE-2022-1417
10.05.2022, 21:15
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobsEnginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 8.12.0 ≤ 𝑥 < 14.8.6 |
gitlab | gitlab | 8.12.0 ≤ 𝑥 < 14.8.6 |
gitlab | gitlab | 14.9.0 ≤ 𝑥 < 14.9.4 |
gitlab | gitlab | 14.9.0 ≤ 𝑥 < 14.9.4 |
gitlab | gitlab | 14.10.0 |
gitlab | gitlab | 14.10.0 |
𝑥
= Vulnerable software versions
References