Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/330047 | broken link |
https://hackerone.com/reports/1182375 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1423.json | third party advisory |