vulnerability
FreeBSD: VID-8657eedd-b423-11ec-9559-001b217b3468 (CVE-2022-1190): Gitlab -- multiple vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:N/AC:M/Au:S/C:N/I:P/A:N) | Apr 4, 2022 | Nov 4, 2022 | Mar 25, 2026 |
Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Apr 4, 2022
Added
Nov 4, 2022
Modified
Mar 25, 2026
Description
Gitlab reports: Static passwords inadvertently set during OmniAuth-based registration Stored XSS in notes Stored XSS on Multi-word milestone reference Denial of service caused by a specially crafted RDoc file GitLab Pages access tokens can be reused on multiple domains GitLab Pages uses default (disabled) server Timeouts and a weak TCP Keep-Alive timeout Incorrect include in pipeline definition exposes masked CI variables in UI Regular expression denial of service in release asset link Latest Commit details from private projects leaked to guest users via Merge Requests CI/CD analytics are available even when public pipelines are disabled Absence of limit for the number of tags that can be added to a runner can cause performance issues Client DoS through rendering crafted comments Blind SSRF Through Repository Mirroring Bypass of branch restriction in Asana integration Readable approval rules by Guest user Redact InvalidURIError error messages Project import maps members' created_by_id users based on source user ID
Solution
freebsd-upgrade-package-gitlab-ce
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.