CVE Vulnerabilities

CVE-2022-0751

Published: Mar 28, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 10.0 (including) 14.6.5 (excluding)
Gitlab Gitlab 14.7 (including) 14.7.4 (excluding)
Gitlab Gitlab 14.8 (including) 14.8.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu trusty *
Gitlab Ubuntu xenial *

References