CVE-2022-4143
Summary
| CVE | CVE-2022-4143 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-28 21:15:00 UTC |
| Updated | 2023-07-06 16:08:00 UTC |
| Description | An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization |
Risk And Classification
Problem Types: CWE-367
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Approved merge request can introduce extra unverified changes without requiring a re-approve (#383776) · Issues · GitLab.org / GitLab · GitLab | MISC | gitlab.com | |
| 2022/CVE-2022-4143.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| HackerOne | MISC | hackerone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks [zzyzxd](https://hackerone.com/zzyzxd) for reporting this vulnerability through our HackerOne bug bounty program
Legacy QID Mappings
- 379225 GitLab CE/EE Time-of-check time-of-use (toctou) Race Condition Vulnerability (CVE-2023-1265)