CVE-2022-2417
05.08.2022, 16:15
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 15.0.5 |
gitlab | gitlab | 15.1.0 ≤ 𝑥 < 15.1.4 |
gitlab | gitlab | 15.2 |
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 15.0.5 |
gitlab | gitlab | 15.1.0 ≤ 𝑥 < 15.1.4 |
gitlab | gitlab | 15.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration