Vulnerability Description
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.3.0, < 14.9.5 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.jsonPatchThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/349750Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.jsonPatchThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/349750Broken Link
FAQ
What is CVE-2022-1944?
CVE-2022-1944 is a vulnerability with a CVSS score of 5.4 (MEDIUM). When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0....
How severe is CVE-2022-1944?
CVE-2022-1944 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1944?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.