CVE-2022-1426
Estado: ModificadaBaja (3.7)—
Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.6 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab no autenticaba correctamente a un usuario que tenía determinada información que le permitía autenticarse sin un token de acceso personal
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.91%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/296866
- https://hackerone.com/reports/1070097
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/296866
- https://hackerone.com/reports/1070097
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-1426",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 0.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@gitlab.com",
"affectedData": [
{
"vendor": "GitLab",
"product": "GitLab",
"versions": [
{
"status": "affected",
"version": ">=12.6, <14.8.6"
},
{
"status": "affected",
"version": ">=14.9, <14.9.4"
},
{
"status": "affected",
"version": ">=14.10, <14.10.1"
}
]
}
]
}
],
"published": "2022-05-11T15:15:08.907",
"references": [
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json",
"tags": [
"Vendor Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/296866",
"tags": [
"Broken Link"
],
"source": "cve@gitlab.com"
},
{
"url": "https://hackerone.com/reports/1070097",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/296866",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/1070097",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token."
},
{
"lang": "es",
"value": "Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.6 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab no autenticaba correctamente a un usuario que tenía determinada información que le permitía autenticarse sin un token de acceso personal"
}
],
"lastModified": "2026-06-17T04:22:25.913",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5F7F0C4-B688-4175-9177-493DA89E4F8B",
"versionEndExcluding": "14.8.6",
"versionStartIncluding": "12.6.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC39EE3A-855E-490C-BDB8-40479B024AE5",
"versionEndExcluding": "14.8.6",
"versionStartIncluding": "12.6.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCD83B23-0868-4545-9E4E-98F0DF151924",
"versionEndExcluding": "14.9.4",
"versionStartIncluding": "14.9.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B4C393E-6B88-4AF8-9071-2C43935A1AEC",
"versionEndExcluding": "14.9.4",
"versionStartIncluding": "14.9.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41411D82-66AE-4AE4-9093-D019F80ED990"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9643D908-345C-48F9-BEDE-08F69EC16931"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@gitlab.com"
}