7.1
CVSSv3

CVE-2022-1944

Published: 06/06/2022 Updated: 13/06/2022
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 before 14.9.5, 14.10 before 14.10.4, and 15.0 before 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 15.0.0