CVE Vulnerabilities

CVE-2022-3706

Published: Nov 10, 2022 | Modified: Nov 11, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesnt have access to that project.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 7.14.0 (including) 15.3.5 (excluding)
Gitlab Gitlab 15.4.0 (including) 15.4.4 (excluding)
Gitlab Gitlab 15.5.0 (including) 15.5.2 (excluding)

References