CVE-2022-3740
EUVD-2022-4309626.01.2023, 21:15
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 12.9.0 ≤ 𝑥 < 15.4.6 |
| gitlab | gitlab | 12.9.0 ≤ 𝑥 < 15.4.6 |
| gitlab | gitlab | 15.5.0 ≤ 𝑥 < 15.5.5 |
| gitlab | gitlab | 15.5.0 ≤ 𝑥 < 15.5.5 |
| gitlab | gitlab | 15.6.0 |
| gitlab | gitlab | 15.6.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References