Aller au contenu

Fiche vulnérabilité

CVE-2022-2533 : faille élevée gitlab gitlab (CVSS 7.4)

Description

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

En bref

Sévérité
Élevée (CVSS 7.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
17 oct. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • gitlab gitlab

Références

Rechercher une autre vulnérabilité dans la base CVE