MEDIUM

CVE-2022-3066

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

Summary dbcve.org

GitLab versions 15.2.x before 15.2.5, 15.3.x before 15.3.4, and 15.4.x before 15.4.1 contain an authorization bypass where unauthenticated or unauthorized users could create issues in projects where they lack proper permissions.

Mitigation

Upgrade GitLab to version 15.2.5, 15.3.4, or 15.4.1 or later. If immediate upgrade is not possible, restrict project creation permissions and audit existing access controls.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

0.57%
Probability of exploitation in next 30 days
45.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE