CVE-2022-2533
Description
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
Summary dbcve.org
GitLab had an authentication bypass in Package Registries where IP address restrictions were not properly enforced. When IP restrictions were configured on Package Registries, a valid Deploy Token could be used from any IP address, bypassing the intended IP allowlist security control.
Mitigation
Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later. Review deployed tokens for suspicious usage and audit Package Registry access logs for any unauthorized IP addresses.