{"api_version":"1","generated_at":"2026-07-23T23:23:41+00:00","cve":"CVE-2022-3285","urls":{"html":"https://cve.report/CVE-2022-3285","api":"https://cve.report/api/cve/CVE-2022-3285.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-3285","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-3285"},"summary":{"title":"CVE-2022-3285","description":"Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2022-11-09 23:15:00","updated_at":"2022-11-11 01:06:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","name":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","refsource":"MISC","tags":[],"title":"Checking your Browser - GitLab","mime":"text/html","httpstatus":"503","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","refsource":"CONFIRM","tags":[],"title":"2022/CVE-2022-3285.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-3285","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3285","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This vulnerability has been discovered internally by the GitLab team","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"3285","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3285","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3285","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3285","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-3285","qid":"690950","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (04422df1-40d8-11ed-9be7-454b1dd82c64)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2022-3285","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=12.0, <15.2.5"},{"version_value":">=15.3, <15.3.4"},{"version_value":">=15.4, <15.4.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper access control in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","url":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab"}]},"impact":{"cvss":{"vectorString":"AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":5.3,"baseSeverity":"MEDIUM"}},"credit":[{"lang":"eng","value":"This vulnerability has been discovered internally by the GitLab team"}]},"nvd":{"publishedDate":"2022-11-09 23:15:00","lastModifiedDate":"2022-11-11 01:06:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.4.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.4.0:*:*:*:community:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.2.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.2.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}