CVE-2022-3286Improper Access Control in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 68.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab14.215.2.5+2
CVEListV5gitlab/gitlab>=14.2, <15.2.5, >=15.3, <15.3.4, >=15.4, <15.4.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2022-3286: Lack of IP address checking in GitLab EE affecting all versions from 142022-10-17
GHSA
GHSA-36p7-jqv6-r5mj: Lack of IP address checking in GitLab EE affecting all versions from 142022-10-17

📋Vendor Advisories

2
GitLab
CVE-2022-3286: Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a gro2022-10-17
Debian
CVE-2022-3286: gitlab - Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior ...2022