VYPR
Medium severity4.3NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026

CVE-2022-1105

CVE-2022-1105

Description

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

Affected products

6
  • GitLab Inc./GitLabv54 versions
    >=13.11, <14.7.7+ 3 more
    • (no CPE)range: >=13.11, <14.7.7
    • (no CPE)range: from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.11.0,<14.7.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.11.0,<14.7.7
  • osv-coords
    Range: >= 13.11.0, < 14.7.7
  • Range: from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.