{"api_version":"1","generated_at":"2026-07-23T23:42:04+00:00","cve":"CVE-2022-3820","urls":{"html":"https://cve.report/CVE-2022-3820","api":"https://cve.report/api/cve/CVE-2022-3820.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-3820","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-3820"},"summary":{"title":"CVE-2022-3820","description":"An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2023-01-26 21:15:00","updated_at":"2023-02-01 17:30:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","refsource":"MISC","tags":[],"title":"IP Group enforcement regression in the Package Registry (#378638) · Issues · GitLab.org / GitLab · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","refsource":"CONFIRM","tags":[],"title":"2022/CVE-2022-3820.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-3820","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3820","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This vulnerability has been discovered internally by the GitLab team.","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"3820","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3820","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3820","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"3820","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-3820","qid":"379229","title":"GitLab Multiple Security Vulnerabilities (gitlab- 15.6.1, 15.5.5, 15.4.6)"},{"cve":"CVE-2022-3820","qid":"690999","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (3cde510a-7135-11ed-a28b-bff032704f00)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2022-3820","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=15.4, <15.4.6"},{"version_value":">=15.5, <15.5.5"},{"version_value":">=15.6, <15.6.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper access control in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location."}]},"impact":{"cvss":{"vectorString":"AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":6.4,"baseSeverity":"MEDIUM"}},"credit":[{"lang":"eng","value":"This vulnerability has been discovered internally by the GitLab team."}]},"nvd":{"publishedDate":"2023-01-26 21:15:00","lastModifiedDate":"2023-02-01 17:30:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}