MEDIUM
CVE-2022-3483
CVSS
5.4
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.
Summary dbcve.org
A malicious GitLab maintainer can modify the Datadog integration URL to redirect authenticated API requests to an attacker-controlled server, enabling exfiltration of the Datadog access token through the integration's outbound HTTP requests.
Mitigation
Upgrade GitLab to version 15.3.5, 15.4.4, 15.5.2 or later to receive the patch.
EPSS Score
0.7%
Probability of exploitation in next 30 days
51.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.