High severity8.6NVD Advisory· Published Jan 18, 2022· Updated Jun 17, 2026
CVE-2022-0244
CVE-2022-0244
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
Affected products
6>=14.5+ 3 more
- (no CPE)range: >=14.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=14.5,<=14.5.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.5,<=14.5.3
- (no CPE)range: >=14.6, <14.6.2
- Range: >=14.5
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/349524nvdBroken LinkVendor Advisory
- hackerone.com/reports/1439593nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.