MEDIUM
CVE-2022-3066
CVSS
5.4
Description
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.
Summary dbcve.org
GitLab versions 15.2.x before 15.2.5, 15.3.x before 15.3.4, and 15.4.x before 15.4.1 contain an authorization bypass where unauthenticated or unauthorized users could create issues in projects where they lack proper permissions.
Mitigation
Upgrade GitLab to version 15.2.5, 15.3.4, or 15.4.1 or later. If immediate upgrade is not possible, restrict project creation permissions and audit existing access controls.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
0.57%
Probability of exploitation in next 30 days
45.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.