{ "id": "CVE-2022-1944", "sourceIdentifier": "cve@gitlab.com", "published": "2022-06-06T17:15:10.867", "lastModified": "2024-11-21T06:41:48.437", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs" }, { "lang": "es", "value": "Cuando la funci\u00f3n est\u00e1 configurada, una autorizaci\u00f3n inapropiada en el Terminal Web Interactivo en GitLab CE/EE que afectando a todas las versiones desde la 11.3 anteriores a 14.9.5, 14.10 anteriores a 14.10.4, y 15.0 anteriores a 15.0.1, permite a usuarios con el rol de Desarrollador abrir terminales en los trabajos en ejecuci\u00f3n de otros Desarrolladores" } ], "metrics": { "cvssMetricV31": [ { "source": "cve@gitlab.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 1.2, "impactScore": 4.2 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 4.2 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N", "baseScore": 4.9, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 6.8, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-863" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "versionStartIncluding": "11.3.0", "versionEndExcluding": "14.9.5", "matchCriteriaId": "68C8C8D5-E965-4291-9825-DD7A9AE0EB5F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "versionStartIncluding": "11.3.0", "versionEndExcluding": "14.9.5", "matchCriteriaId": "15F617DB-515D-46A9-BE58-CA3128108FD2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "versionStartIncluding": "14.10.0", "versionEndExcluding": "14.10.4", "matchCriteriaId": "5E69F4A1-5B3A-4FF5-95EC-62DCEB7DCE5F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "versionStartIncluding": "14.10.0", "versionEndExcluding": "14.10.4", "matchCriteriaId": "4E6B5E02-4670-4E74-A3EA-DF81659861E1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*", "matchCriteriaId": "00FDE831-EC28-4124-AC9F-A1C089D5BBFA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*", "matchCriteriaId": "E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5" } ] } ] } ], "references": [ { "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json", "source": "cve@gitlab.com", "tags": [ "Patch", "Third Party Advisory" ] }, { "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/349750", "source": "cve@gitlab.com", "tags": [ "Broken Link" ] }, { "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ] }, { "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/349750", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link" ] } ] }