CVE-2022-0751 is a high-severity vulnerability affecting all versions of GitLab CE/EE, where an attacker can craft Snippet files with special characters that display inaccurately. This allows for the creation of misleading content, potentially tricking users into executing arbitrary commands. The vulnerability has a CVSS score of 8.8 (HIGH) due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impact. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, and community discussion and media coverage are limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, < 14.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.0, < 14.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 14.7, < 14.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 14.7, < 14.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 14.8, < 14.8.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.