8
CVSSv3

CVE-2022-2251

Published: 17/01/2023 Updated: 08/08/2023
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

Improper sanitization of branch names in GitLab Runner affecting all versions before 15.3.5, 15.4 before 15.4.4, and 15.5 before 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab runner