CVE-2022-1460 log

Source
Severity Medium
Remote Unknown
Type Access restriction bypass
Description
GitLab all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1 was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.
Group Package Affected Fixed Severity Status Ticket
AVG-2696 gitlab 14.10-1 14.10.2-1 High Fixed