CVE-2022-2533
published 2022-10-17CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions…
PriorityP342high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.65%
46.7th percentile
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 15.10.8+ds1-2 (sid) | gitlab 15.10.8+ds1-2 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 12.10 < 15.1.6 | 15.1.6 |
| gitlab | gitlab | >= 15.2 < 15.2.4 | 15.2.4 |
| gitlab | gitlab | >= 15.3 < 15.3.2 | 15.3.2 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GitLab up to 15.1.5/15.2.3/15.3.1 Package Registry improper authentication (Issue 36386 / EUVD-2022-34787)
vuldb·2026-05-26·CVSS 7.4
CVE-2022-2533 [HIGH] GitLab up to 15.1.5/15.2.3/15.3.1 Package Registry improper authentication (Issue 36386 / EUVD-2022-34787)
A vulnerability, which was classified as critical, was found in GitLab up to 15.1.5/15.2.3/15.3.1. This issue affects some unknown processing of the component Package Registry Handler. Such manipulation leads to improper authentication.
This vulnerability is traded as CVE-2022-2533. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
OSV
CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12
osv·2022-10-17·CVSS 7.4
CVE-2022-2533 [HIGH] CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
GHSA
GHSA-mx6m-x365-fxj7: An issue has been discovered in GitLab affecting all versions starting from 12
ghsa_unreviewed·2022-10-17
CVE-2022-2533 [HIGH] CWE-287 GHSA-mx6m-x365-fxj7: An issue has been discovered in GitLab affecting all versions starting from 12
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
GitLab
CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all ve
vendor_gitlab·2022-10-17·CVSS 6.5
CVE-2022-2533 [MEDIUM] CWE-287 CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all ve
CVE-2022-2533: An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
Debian
CVE-2022-2533: gitlab - An issue has been discovered in GitLab affecting all versions starting from 12.1...
vendor_debian·2022·CVSS 6.5
CVE-2022-2533 [MEDIUM] CVE-2022-2533: gitlab - An issue has been discovered in GitLab affecting all versions starting from 12.1...
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
Scope: local
sid: resolved (fixed in 15.10.8+ds1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-17
Published