| Vulnerability Name: | CVE-2022-0172 (CCN-217485) | ||||||||||||
| Assigned: | 2022-01-17 | ||||||||||||
| Published: | 2022-01-17 | ||||||||||||
| Updated: | 2022-01-25 | ||||||||||||
| Summary: | An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones. | ||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:U/RC:R)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||
| CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-863 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2022-0172 Source: XF Type: UNKNOWN gitlab-cve20220172-sec-bypass(217485) Source: CCN Type: GitLab Web site CVE-2022-0172 Source: CONFIRM Type: Third Party Advisory https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0172.json Source: MISC Type: Broken Link https://gitlab.com/gitlab-org/gitlab/-/issues/348411 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||