HIGH
CVE-2022-4167
CVSS
7.5
Description
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
Summary dbcve.org
An incorrect authorization check in GitLab EE allows group access tokens to remain functional even after a group owner loses the ability to revoke them. This is a broken access control vulnerability where tokens that should be invalidated following a permission change continue to work.
Mitigation
Upgrade GitLab EE to version 15.5.7, 15.6.4, or 15.7.2 or later to remediate the authorization bypass.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.54%
Probability of exploitation in next 30 days
44.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.