Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2095
HistoryAug 05, 2022 - 4:15 p.m.

Improper access control

2022-08-0516:15:00
PRIOn knowledge base
www.prio-n.com
9
gitlab
access control
vulnerability
public project
git
malicious user
nvd

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

29.7%

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project’s Deploy Key’s public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

29.7%