CVE-2022-3820
Published on: Not Yet Published
Last Modified on: 02/01/2023 05:30:00 PM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
- CVE-2022-3820 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitLab - GitLab version >=15.4, <15.4.6
- Affected Vendor/Software:
GitLab - GitLab version >=15.5, <15.5.5
- Affected Vendor/Software:
GitLab - GitLab version >=15.6, <15.6.1
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
IP Group enforcement regression in the Package Registry (#378638) · Issues · GitLab.org / GitLab · GitLab | gitlab.com text/html |
![]() |
2022/CVE-2022-3820.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
Related QID Numbers
- 690999 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (3cde510a-7135-11ed-a28b-bff032704f00)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*:
Discovery Credit
This vulnerability has been discovered internally by the GitLab team.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
[email protected] #Vulnerability of ArcGIS Server: directory traversal. vigilance.fr/vulnerability/… Identifiers: #CVE-2022-3820… twitter.com/i/web/status/1… | 2022-12-29 12:09:04 |