Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2022-2417
Published: July 29, 2022
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote administrator can import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.
Affected software
Gitlab Community Edition
How to mitigate CVE-2022-2417
Gitlab Community Edition - addressed in versions 15.0.5, 15.1.4, 15.2.1