An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-03T00:24:44.172Z

Reserved: 2022-06-16T00:00:00

Link: CVE-2022-2095

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-05T16:15:11.617

Modified: 2024-11-21T07:00:18.647

Link: CVE-2022-2095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.