Home » Database

AVID-2026-R0996

Description

Vulnerability CVE-2022-2417

Details

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

Reason for inclusion in AVID: The CVE describes a vulnerability in GitLab that can be exploited via crafted branch names to facilitate supply chain attacks by manipulating pinned commits. GitLab is a core component used in software supply chains and commonly used in AI development pipelines (CI/CD, artifact hosting). This is a security vulnerability with clear impact on integrity, and the report provides signal (CVE entry, description, CVSS). Therefore it should be curated as a vulnerability in the AI supply chain.

References

Affected or Relevant Artifacts

  • Developer: GitLab
  • Deployer: GitLab
  • Artifact Details:
TypeName
SystemGitLab

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
Base Score6.2
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🔴 High
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactNONE
Integrity Impact🔴 High
Availability ImpactNONE

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-08-05
  • Version: 0.3.3
  • AVID Entry