S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0735 Scanner

CVE-2022-0735 scanner - Information Disclosure vulnerability in GitLab

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0735
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GitLabby GitLab
>=14.8, <14.8.2
Updated Aug 22, 2026View on NVD →
Detail

GitLab is a web-based Git repository manager that enables software architects, developers and operations teams to coordinate their work on software code and manage their projects from a single platform. It supports Agile and DevOps methodologies, making it an extremely valuable tool for modern software development. GitLab enables teams to monitor code changes, automate the build, test and deployment process, and track project milestones.

One of the vulnerabilities discovered in GitLab is identified by its Common Vulnerabilities and Exposures (CVE) code - CVE-2022-0735. The vulnerability affects all versions of GitLab CE/EE from 12.10 before 14.6.5, all versions from 14.7 before 14.7.4, and all versions from 14.8 before 14.8.2. The vulnerability operates by an unauthorized actor being able to gain information disclosure rights and steal runner registration tokens via quick action commands. This means that a hacker can obtain access to confidential information about the desired code path, as well as potentially cause severe long-term damage.

Exploitation of CVE-2022-0735 could lead to a number of disastrous outcomes. For example, a malicious attacker could easily gain access to debit and credit card information, financial data, or sensitive user data. They could also manipulate the code of the software, install malware on the system, or gain access to privileged information that could harm a company or customer base. Malicious cyberattacks can lead to compromised security, reputation loss, financial penalties, and even legal action against the offending party.

In summary, GitLab is a powerful tool for software development, but it is not immune to cybersecurity threats such as CVE-2022-0735. Those who depend on GitLab should take the necessary precautions to safeguard their digital assets and sensitive information. With the help of a platform like s4e.io, they can quickly and efficiently identify vulnerabilities in their systems and protect their assets from exploitation.

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, the following precautionary measures should be taken:

  • Upgrade to a patched version of GitLab.
  • Implement role-based access controls on the repository.
  • Consider disabling quick actions commands to make it more difficult for an unauthorized user to gain access.
  • Educate employees on the importance of cybersecurity practices, including creating complex passwords, avoiding phishing attempts, and being mindful of suspicious emails or messages.
  • Use anti-malware and antivirus software to detect and prevent intrusions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0735 scanner - Information Disclosure vulnerability in GitLab | S4E