CVE-2022-4167Incorrect Authorization in Gitlab

Severity
7.5HIGHNVD
EPSS
0.2%
top 58.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12

Description

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab13.11.015.5.7+2
CVEListV5gitlab/gitlab>=13.11, <15.5.7, >=15.6, <15.6.4, >=15.7, <15.7.2+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-wf4m-rq68-3mfc: Incorrect Authorization check affecting all versions of GitLab EE from 132023-01-12
OSV
CVE-2022-4167: Incorrect Authorization check affecting all versions of GitLab EE from 132023-01-12

📋Vendor Advisories

2
GitLab
CVE-2022-4167: Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows gr2023-01-12
Debian
CVE-2022-4167: gitlab - Incorrect Authorization check affecting all versions of GitLab EE from 13.11 pri...2022