4.5
CVSSv3

CVE-2022-2417

Published: 05/08/2022 Updated: 11/08/2022
CVSS v3 Base Score: 4.5 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 0

Vulnerability Summary

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 15.2

Vendor Advisories

gitlab allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project ...