HIGH

CVE-2022-2533

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
7.4

Description

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

Summary dbcve.org

GitLab had an authentication bypass in Package Registries where IP address restrictions were not properly enforced. When IP restrictions were configured on Package Registries, a valid Deploy Token could be used from any IP address, bypassing the intended IP allowlist security control.

Mitigation

Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later. Review deployed tokens for suspicious usage and audit Package Registry access logs for any unauthorized IP addresses.

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

0.71%
Probability of exploitation in next 30 days
52.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE