CVE-2022-1460

Publication date 11 May 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

4.9 · Medium

Score breakdown

Description

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

Status


Severity score breakdown

Parameter Value
Base score 4.9 · Medium
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Access our resources on patching vulnerabilities