HIGH

CVE-2022-4167

Gitlab GitLab 2023-01-12 CVSS v3.1
CVSS
7.5

Description

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

Summary dbcve.org

An incorrect authorization check in GitLab EE allows group access tokens to remain functional even after a group owner loses the ability to revoke them. This is a broken access control vulnerability where tokens that should be invalidated following a permission change continue to work.

Mitigation

Upgrade GitLab EE to version 15.5.7, 15.6.4, or 15.7.2 or later to remediate the authorization bypass.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.54%
Probability of exploitation in next 30 days
44.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE