CVE-2022-2498
Last modified
CVE-2022-2498 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 12.8.0, < 15.0.5 |
| Gitlab | Gitlab | >= 15.1.0, < 15.1.4 |
| Gitlab | Gitlab | 15.2 |
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/243703Broken Link, Vendor Advisory
- https://hackerone.com/reports/966824Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/243703Broken Link, Vendor Advisory
- https://hackerone.com/reports/966824Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2498?
How severe is CVE-2022-2498?
How do I fix CVE-2022-2498?
Are you affected by CVE-2022-2498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
