Unrated severityNVD Advisory· Published May 11, 2022· Updated Aug 2, 2024
CVE-2022-1124
CVE-2022-1124
Description
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
Affected products
3- Range: <14.8.6, >=14.9.0 <14.9.4, =14.10.0
- Range: <14.8.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.jsonmitrex_refsource_CONFIRM
- gitlab.com/gitlab-org/gitlab/-/issues/323552mitrex_refsource_MISC
- hackerone.com/reports/1113405mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.