Medium severity4.3NVD Advisory· Published May 11, 2022· Updated Jun 17, 2026
CVE-2022-1124
CVE-2022-1124
Description
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <14.8.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <14.8.6
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*
- (no CPE)range: <14.8.6, 14.9.0 to <14.9.4, 14.10.0
- (no CPE)range: <14.8.6
- Range: <14.8.6, 14.9.0 to <14.9.4, 14.10.0
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.jsonnvdVendor Advisory
- hackerone.com/reports/1113405nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/323552nvdBroken Link
News mentions
0No linked articles in our index yet.