MEDIUM

CVE-2022-3483

Gitlab GitLab 2022-11-09 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

Summary dbcve.org

A malicious GitLab maintainer can modify the Datadog integration URL to redirect authenticated API requests to an attacker-controlled server, enabling exfiltration of the Datadog access token through the integration's outbound HTTP requests.

Mitigation

Upgrade GitLab to version 15.3.5, 15.4.4, 15.5.2 or later to receive the patch.

EPSS Score

0.7%
Probability of exploitation in next 30 days
51.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE