CVE Vulnerabilities

CVE-2022-3325

Published: Oct 17, 2022 | Modified: Aug 08, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.8.0 (including) 15.2.5 (excluding)
Gitlab Gitlab 15.3 (including) 15.3.4 (excluding)
Gitlab Gitlab 15.4 (including) 15.4.1 (excluding)

References