Vulnerability CVE-2022-0735


Published: 2022-03-28

Description:
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

Type:

CWE-863

(Incorrect Authorization)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Gitlab -> Gitlab 

 References:
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json
https://gitlab.com/gitlab-org/gitlab/-/issues/353529

Copyright 2026, cxsecurity.com

 

Back to Top