← All CVEs

CVE-2022-0735

critical · 10

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

10
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2022-03-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

VendorProductAffected versions
gitlabgitlab>= 12.0, < 14.6.5
gitlabgitlab>= 12.0, < 14.6.5
gitlabgitlab>= 14.7, < 14.7.4
gitlabgitlab>= 14.7, < 14.7.4
gitlabgitlab>= 14.8, < 14.8.2
gitlabgitlab>= 14.8, < 14.8.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-0735