CVE-2022-1983Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 67.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateOct 1

Description

Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab10.7.014.10.5+2
CVEListV5gitlab/gitlab>=10.7, <14.10.5, >=15.0, <15.0.4, >=15.1, <15.1.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-8fph-2g4q-jf26: Incorrect authorization in GitLab EE affecting all versions from 102022-07-02
OSV
CVE-2022-1983: Incorrect authorization in GitLab EE affecting all versions from 102022-07-01

📋Vendor Advisories

3
Red Hat
kernel: mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING2025-10-01
GitLab
CVE-2022-1983: Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an att2022-07-01
Debian
CVE-2022-1983: gitlab - Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 1...2022