MEDIUM

CVE-2022-3067

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

Summary dbcve.org

The Import functionality in GitLab CE/EE contains an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users to read arbitrary project contents by knowing the project's ID, even without proper authorization to those projects.

Mitigation

Upgrade to GitLab 15.2.5, 15.3.4, 15.4.1 or later. Review and enforce project access controls to ensure users can only access projects they are explicitly authorized to view.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

0.77%
Probability of exploitation in next 30 days
54.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE