CVE Vulnerabilities

CVE-2022-3706

Published: Nov 10, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesnt have access to that project.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab7.14.0 (including)15.3.5 (excluding)
GitlabGitlab15.4.0 (including)15.4.4 (excluding)
GitlabGitlab15.5.0 (including)15.5.2 (excluding)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntutrusty*
GitlabUbuntuxenial*

References